Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 30 May 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eregistrasi-kejuaraan-silat
Eregistrasi-kejuaraan-silat registrasi Pencak Silat |
|
| Vendors & Products |
Eregistrasi-kejuaraan-silat
Eregistrasi-kejuaraan-silat registrasi Pencak Silat |
Fri, 29 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id_partai parameter. Attackers can send GET requests to monitor_nilai.php with crafted SQL payloads in the id_partai parameter to extract sensitive database information including admin credentials and user data. | |
| Title | E-Registrasi Pencak Silat 18.10 SQL Injection via id_partai | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-29T20:20:24.356Z
Reserved: 2026-05-29T11:13:55.327Z
Link: CVE-2018-25385
Updated: 2026-05-29T20:20:21.057Z
Status : Deferred
Published: 2026-05-29T16:16:17.587
Modified: 2026-05-29T16:29:11.350
Link: CVE-2018-25385
No data.
OpenCVE Enrichment
Updated: 2026-05-30T21:18:59Z