HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows attackers to change administrator passwords by submitting forged requests to the user update endpoint. Attackers can craft malicious forms targeting the aksi_user.php script with parameters like id_user, password, and level to modify admin credentials without authentication.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 29 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HaPe PKH 1.1 contains a cross-site request forgery vulnerability that allows attackers to change administrator passwords by submitting forged requests to the user update endpoint. Attackers can craft malicious forms targeting the aksi_user.php script with parameters like id_user, password, and level to modify admin credentials without authentication. | |
| Title | HaPe PKH 1.1 Cross-Site Request Forgery via aksi_user.php | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-29T14:46:31.802Z
Reserved: 2026-05-29T11:16:38.154Z
Link: CVE-2018-25387
No data.
Status : Deferred
Published: 2026-05-29T16:16:17.853
Modified: 2026-05-29T16:29:11.350
Link: CVE-2018-25387
No data.
OpenCVE Enrichment
Updated: 2026-05-29T17:30:04Z
Weaknesses