Record summary

CVE-2021-47848 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.

Description

Blitar Tourism 1.0 contains an authentication bypass vulnerability that allows attackers to bypass login by injecting SQL code through the username parameter. Attackers can manipulate the login request by sending a crafted username with SQL injection techniques to gain unauthorized administrative access.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 22, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List1.0affected

Proofs of concept

1

Catalogued exploits

ExploitDBBlitar Tourism 1.0 - Authentication Bypass SQLiExploitDB exploitby sigeri94Not analyzed1 file
ExploitDB

PoC details

References

4