SQL Injection Vulnerability in HaPe PKH by SiteJo
CVE-2018-25390

8.8HIGH

Key Information:

Vendor

Sitejo

Status
Vendor
CVE Published:
29 May 2026

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2018-25390?

HaPe PKH version 1.1 is susceptible to an SQL injection vulnerability, which allows unauthorized users to alter database queries by injecting malicious SQL code through the 'desa' POST parameter in the lap-peserta-perdesa-pdf.php script. This exploit enables attackers to perform time-based blind SQL injection, giving them the ability to infer and extract sensitive information from the database, potentially compromising the integrity and confidentiality of the data stored.

Affected Version(s)

HaPe PKH 1.1

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ihsan Sencan
.