


Perceptive Security
SOC/SIEM Consultancy

HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to delete arbitrary records by sending a crafte…
Published:
28 mei 2026 om 22:00:00
Alert date:
29 mei 2026 om 17:11:07
Source:
nvd.nist.gov
Web Technologies, Identity & Access
CVE-2018-25391 affects HaPe PKH version 1.1, a vulnerability that allows unauthenticated attackers to delete arbitrary records without proper authorization checks. The flaw exists in two specific endpoints: admin/modul/mod_pengurus/aksi_pengurus.php and admin/modul/mod_update/aksi_update.php. Attackers can exploit this by sending crafted requests with target record IDs to delete administrator and update records. The vulnerability represents a critical authorization bypass that could lead to data loss and system compromise. No authentication is required to exploit this flaw, making it particularly dangerous for exposed systems.
Technical details
Mitigation steps:
Affected products:
HaPe PKH 1.1
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2018-25391
http://www.sitejo.id
https://sourceforge.net/projects/hape-pkh/files/latest/download
https://www.exploit-db.com/exploits/45588
https://www.vulncheck.com/advisories/hape-pkh-missing-authorization-allows-unauthenticated-record-deletion
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
