Blitar Tourism 1.0 contains an authentication bypass vulnerability that allows attackers to bypass login by injecting SQL code through the username parameter. Attackers can manipulate the login request by sending a crafted username with SQL injection techniques to gain unauthorized administrative access.
Metrics
Affected Vendors & Products
References
History
Fri, 23 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Satndy
Satndy aplikasi-biro-travel |
|
| Vendors & Products |
Satndy
Satndy aplikasi-biro-travel |
Thu, 22 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 21 Jan 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Blitar Tourism 1.0 contains an authentication bypass vulnerability that allows attackers to bypass login by injecting SQL code through the username parameter. Attackers can manipulate the login request by sending a crafted username with SQL injection techniques to gain unauthorized administrative access. | |
| Title | Blitar Tourism 1.0 - Authentication Bypass SQLi | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-22T15:52:57.546Z
Reserved: 2026-01-14T17:11:19.902Z
Link: CVE-2021-47848
Updated: 2026-01-22T15:52:54.657Z
Status : Received
Published: 2026-01-21T18:16:13.890
Modified: 2026-01-21T18:16:13.890
Link: CVE-2021-47848
No data.