← Zurück zur CVE-Suche

CVE-2018-25388

HaPe PKH

Beschreibung

HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload PHP files through multiple endpoints including aksi_foto.php, aksi_user.php, and aksi_kecamatan.php to execute arbitrary code on the server.

CVSS 8.8EPSS 0.519%Risiko 0.92
Quelle öffnen
Veröffentlicht
2026-05-29 16:16:17
Betroffene Versionen
==1.1
Typ
Package
Zuletzt geändert
2026-07-21 12:10:00
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H