Aplikasi Biro Travel GitHub Repositoryproduct
https://github.com/satndy/Aplikasi-Biro-Travel CVE-2021-47848
HIGH
Blitar Tourism 1.0 - Authentication Bypass SQLi
Record summary
CVE-2021-47848 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
Blitar Tourism 1.0 contains an authentication bypass vulnerability that allows attackers to bypass login by injecting SQL code through the username parameter. Attackers can manipulate the login request by sending a crafted username with SQL injection techniques to gain unauthorized administrative access.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 22, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Aplikasi-Biro-TravelBrowse satndy / Aplikasi-Biro-Travel | CVE List | 1.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBBlitar Tourism 1.0 - Authentication Bypass SQLiExploitDB exploitby sigeri94Not analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47848 ExploitDB-49759exploit
https://www.exploit-db.com/exploits/49759 VulnCheck Advisory: Blitar Tourism 1.0 - Authentication Bypass SQLiThird-party advisory
https://www.vulncheck.com/advisories/blitar-tourism-authentication-bypass-sqli