


Perceptive Security
SOC/SIEM Consultancy

HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. At…
Published:
28 mei 2026 om 22:00:00
Alert date:
29 mei 2026 om 17:11:09
Source:
nvd.nist.gov
Web Technologies
HaPe PKH version 1.1 contains a critical arbitrary file upload vulnerability that allows authenticated attackers to bypass file type validation and upload malicious PHP files. The vulnerability affects multiple endpoints including aksi_foto.php, aksi_user.php, and aksi_kecamatan.php, enabling attackers to execute arbitrary code on the server. This represents a significant security risk as it can lead to complete server compromise through remote code execution. The vulnerability has been documented with CVE-2018-25388 and exploit code is publicly available.
Technical details
Mitigation steps:
Affected products:
HaPe PKH 1.1
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2018-25388
http://www.sitejo.id
https://sourceforge.net/projects/hape-pkh/files/latest/download
https://www.exploit-db.com/exploits/45593
https://www.vulncheck.com/advisories/hape-pkh-arbitrary-file-upload-via-aksi-foto-php
Related CVE's:
Related threat actors:
IOC's:
aksi_foto.php, aksi_user.php, aksi_kecamatan.php
This article was created with the assistance of AI technology by Perceptive.
