top of page
perceptive_background_267k.jpg

HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to delete arbitrary records by sending a crafte…

Published:

28 mei 2026 om 22:00:00

Alert date:

29 mei 2026 om 17:11:07

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

CVE-2018-25391 affects HaPe PKH version 1.1, a vulnerability that allows unauthenticated attackers to delete arbitrary records without proper authorization checks. The flaw exists in two specific endpoints: admin/modul/mod_pengurus/aksi_pengurus.php and admin/modul/mod_update/aksi_update.php. Attackers can exploit this by sending crafted requests with target record IDs to delete administrator and update records. The vulnerability represents a critical authorization bypass that could lead to data loss and system compromise. No authentication is required to exploit this flaw, making it particularly dangerous for exposed systems.

Technical details

Mitigation steps:

Affected products:

HaPe PKH 1.1

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page