Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 30 May 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sitejo
Sitejo hape Pkh |
|
| Vendors & Products |
Sitejo
Sitejo hape Pkh |
Fri, 29 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to delete arbitrary records by sending a crafted request that specifies the target record's id. The admin/modul/mod_pengurus/aksi_pengurus.php (module=pengurus&act=hapus) and admin/modul/mod_update/aksi_update.php (module=update&act=hapus) endpoints process deletions without verifying the requester's privileges, enabling removal of pengurus (administrator) and update records. | |
| Title | HaPe PKH 1.1 Missing Authorization Allows Unauthenticated Record Deletion | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-29T19:25:37.368Z
Reserved: 2026-05-29T11:24:03.699Z
Link: CVE-2018-25391
Updated: 2026-05-29T19:25:30.580Z
Status : Deferred
Published: 2026-05-29T16:16:18.380
Modified: 2026-05-29T16:29:11.350
Link: CVE-2018-25391
No data.
OpenCVE Enrichment
Updated: 2026-05-30T21:18:51Z