Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 01 Jun 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 30 May 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Simpkh
Simpkh sim-pkh |
|
| Vendors & Products |
Simpkh
Simpkh sim-pkh |
Sat, 30 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SIM-PKH 2.4.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send GET requests to /admin/media.php with module=pengurus and act=editpengurus parameters containing SQL UNION statements to extract database information including usernames, database names, and version details. | |
| Title | SIM-PKH 2.4.1 SQL Injection via media.php id Parameter | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-01T15:12:41.677Z
Reserved: 2026-05-30T12:27:11.523Z
Link: CVE-2018-25410
Updated: 2026-06-01T15:12:36.701Z
Status : Deferred
Published: 2026-05-30T16:17:01.723
Modified: 2026-06-01T16:51:36.193
Link: CVE-2018-25410
No data.
OpenCVE Enrichment
Updated: 2026-05-30T21:17:46Z