CVE-2018-25388
HaPe PKH 1.1 Arbitrary File Upload via aksi_foto.php
Vexday Risk Score
41Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 8.7EPSS 0.5%KEV nãoPoC públicaNuclei —Metasploit —Patch —
Lifecycle
29 May 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload PHP files through multiple endpoints including aksi_foto.php, aksi_user.php, and aksi_kecamatan.php to execute arbitrary code on the server.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Sitejo · HaPe PKHpublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/45593unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.