Vulnerability Description
HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'desa' POST parameter sent to lap-peserta-perdesa-pdf.php. Attackers can send a crafted request with a time-based blind payload to infer and extract sensitive database information.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- http://www.sitejo.id
- https://sourceforge.net/projects/hape-pkh/files/latest/download
- https://www.exploit-db.com/exploits/45588
- https://www.vulncheck.com/advisories/hape-pkh-sql-injection-via-desa-parameter
FAQ
What is CVE-2018-25390?
CVE-2018-25390 is a vulnerability with a CVSS score of 8.2 (HIGH). HaPe PKH 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'desa' POST parameter sent to lap-peserta-pe...
How severe is CVE-2018-25390?
CVE-2018-25390 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-25390?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.