CVE-2018-25388: Sitejo Hape Pkh

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

HaPe PKH 1.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by bypassing file type validation. Attackers can upload PHP files through multiple endpoints including aksi_foto.php, aksi_user.php, and aksi_kecamatan.php to execute arbitrary code on the server.

Affected products

  • Sitejo Hape Pkh: version 1.1 only

Published 2026-05-29. Last modified 2026-07-21.