Junglewise Threat Intelligence

CVE-2018-25391: HaPe PKH missing authorization in record deletion endpoints

CVE-2018-25391 · Severity: high · CVSS 7.5 · Published 2026-05-29

Technologies: HaPe PKH Project HaPe PKH.

Executive brief

HaPe PKH is a web-based application used for managing social assistance program data. A security flaw in the software allows anyone on the internet to delete administrative and update records without needing a password. This could lead to significant data loss and disruption of the program's management operations.

Technical details

A missing authorization vulnerability (CWE-862) exists in HaPe PKH version 1.1 and earlier. The application fails to verify user privileges on specific administrative endpoints, specifically 'admin/modul/mod_pengurus/aksi_pengurus.php' and 'admin/modul/mod_update/aksi_update.php'. An unauthenticated remote attacker can exploit this by sending a direct HTTP request with the 'act=hapus' parameter and a target 'id'. This allows for the unauthorized deletion of 'pengurus' (administrator) and 'update' records. No user interaction or prior authentication is required for a successful exploit.

Affected products

  • HaPe PKH Project HaPe PKH 1.1 and earlier

Timeline

  • 2018-10-12: disclosed: Initial exploit code published on Exploit-DB
  • 2026-05-29: advisory: CVE-2018-25391 published by VulnCheck

References

Related threats