SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by submitting PHP code through the fupload parameter. Attackers can upload PHP files via the aksi_pengurus.php endpoint with module=pengurus and act=update parameters, which are stored in the foto directory and executed as web scripts.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 30 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SIM-PKH 2.4.1 contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by submitting PHP code through the fupload parameter. Attackers can upload PHP files via the aksi_pengurus.php endpoint with module=pengurus and act=update parameters, which are stored in the foto directory and executed as web scripts. | |
| Title | SIM-PKH 2.4.1 Arbitrary File Upload via aksi_pengurus.php | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-30T14:55:16.382Z
Reserved: 2026-05-30T12:26:46.782Z
Link: CVE-2018-25409
No data.
Status : Received
Published: 2026-05-30T16:17:01.587
Modified: 2026-05-30T16:17:01.587
Link: CVE-2018-25409
No data.
OpenCVE Enrichment
Updated: 2026-05-30T16:30:27Z
Weaknesses