PT-2026-44869 · Undefined · Undefined

Published

2026-05-29

·

Updated

2026-05-29

·

CVE-2018-25391

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
HaPe PKH 1.1 fails to enforce authorization on its record deletion endpoints, allowing unauthenticated attackers to delete arbitrary records by sending a crafted request that specifies the target record's id. The admin/modul/mod pengurus/aksi pengurus.php (module=pengurus&act=hapus) and admin/modul/mod update/aksi update.php (module=update&act=hapus) endpoints process deletions without verifying the requester's privileges, enabling removal of pengurus (administrator) and update records.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2018-25391

Affected Products

Undefined