SQL Injection Vulnerability in HaPe PKH by SiteJo
CVE-2018-25390
8.8HIGH
What is CVE-2018-25390?
HaPe PKH version 1.1 is susceptible to an SQL injection vulnerability, which allows unauthorized users to alter database queries by injecting malicious SQL code through the 'desa' POST parameter in the lap-peserta-perdesa-pdf.php script. This exploit enables attackers to perform time-based blind SQL injection, giving them the ability to infer and extract sensitive information from the database, potentially compromising the integrity and confidentiality of the data stored.
Affected Version(s)
HaPe PKH 1.1
References
CVSS V4
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
Ihsan Sencan
