← back
CVE-2018-25388

HaPe PKH 1.1 Arbitrary File Upload via aksi_foto.php

CVSS 8.7 HIGHEPSS 0.5%CWE-434
Vexday Risk Score
41Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 8.7EPSS 0.5%KEV nãoPoC públicaNuclei Metasploit Patch
Lifecycle
29 May 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload PHP files through multiple endpoints including aksi_foto.php, aksi_user.php, and aksi_kecamatan.php to execute arbitrary code on the server.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Sitejo · HaPe PKH
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.