CVE-2018-25385

HIGH

E-Registrasi Pencak Silat 18.10 SQL Injection via id_partai

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-25385. PoCs published by Ihsan Sencan.

AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in E-Registrasi Pencak Silat 18.10 via the 'id_partai' parameter in the 'nilai/monitor_nilai.php' endpoint. The provided URL-encoded payload is designed to execute arbitrary SQL commands, confirming the vulnerability.

Description

E-Registrasi Pencak Silat 18.10 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id_partai parameter. Attackers can send GET requests to monitor_nilai.php with crafted SQL payloads in the id_partai parameter to extract sensitive database information including admin credentials and user data.

Exploits (1)

exploitdb WORKING POC
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/45582

The exploit demonstrates a SQL injection vulnerability in E-Registrasi Pencak Silat 18.10 via the 'id_partai' parameter in the 'nilai/monitor_nilai.php' endpoint. The provided URL-encoded payload is designed to execute arbitrary SQL commands, confirming the vulnerability.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: E-Registrasi Pencak Silat 18.10
No auth needed
Prerequisites: Access to the vulnerable endpoint
devstral-2 · analyzed May 29, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-45582
https://www.exploit-db.com/exploits/45582
Product product
Official Product Homepage
https://sourceforge.net/projects/eregistrasi-kejuaraan-silat/
Third Party Advisory third-party-advisory
VulnCheck Advisory: E-Registrasi Pencak Silat 18.10 SQL Injection via id_partai
https://www.vulncheck.com/advisories/e-registrasi-pencak-silat-sql-injection-via-id-partai

Scores

CVSS v3 8.2
EPSS 0.0033
EPSS Percentile 25.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
eregistrasi-kejuaraan-silat/Registrasi Pencak Silat 18.10
Published May 29, 2026
Tracked Since May 29, 2026