CVE-2018-25391
HIGHHaPe PKH 1.1 Missing Authorization Allows Unauthenticated Record Deletion
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2018-25391. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary The exploit demonstrates multiple SQL injection vulnerabilities in HaPe PKH 1.1 via crafted HTTP requests. It includes payloads for various endpoints, leveraging time-based and error-based SQLi techniques to extract data or manipulate queries.
Description
HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to delete arbitrary records by sending a crafted request that specifies the target record's id. The admin/modul/mod_pengurus/aksi_pengurus.php (module=pengurus&act=hapus) and admin/modul/mod_update/aksi_update.php (module=update&act=hapus) endpoints process deletions without verifying the requester's privileges, enabling removal of pengurus (administrator) and update records.
Exploits (1)
The exploit demonstrates multiple SQL injection vulnerabilities in HaPe PKH 1.1 via crafted HTTP requests. It includes payloads for various endpoints, leveraging time-based and error-based SQLi techniques to extract data or manipulate queries.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N