Zero Entry Hacking and Common Vulnerability Scoring System (CVSS) Apisi Website
Keywords:
Information System Security, Association, Library, SLiMS, WordPress, Zero Entry HackingAbstract
The current development of information technology encourages non-profit organizations to utilize web-based information systems to support their public services. However, along with this utilization, the issue of information system security has become crucial due to the high frequency of cyber-attacks. This study aims to identify vulnerabilities, conduct penetration testing, and measure the level of security risk on the main portal (http://apisi.org) and library information system (http://opac.apisi.org) belonging to the Indonesian School Information Professionals Association (APISI). This experimental study applies the Zero Entry Hacking (ZEH) methodology which includes four main phases: Reconnaissance, Scanning, Exploitation, and Post-Exploitation. The results of comprehensive testing using various security audit tools detected a total of 41 vulnerabilities in the APISI information system. Based on the measurement results using the Common Vulnerability Scoring System (CVSS) v3.1 calculator, 2 vulnerabilities were found to be categorized as Critical and 9 vulnerabilities to be categorized as High. Overall, the APISI website has an average vulnerability level of 6.6 on a scale of 10, which is included in the medium risk category. The exploit successfully demonstrated the execution of a Cross-Site Scripting (XSS) attack on the OPAC and the upload of a backdoor using Weevely, which granted full control over the server directory. Recommendations included establishing a security Standard Operating Procedure (SOP) and closing the security gap by regularly updating the software version.
References
1. Althonayan, A., & Andronache, A. (2018, September). Shifting from information security towards a cybersecurity paradigm. In Proceedings of the 2018 10th International Conference on Information Management and Engineering (pp. 68-79).
2. Anchugam, C. V. (2021). Essential security elements and phases of hacking attacks. In Ethical hacking techniques and countermeasures for cybercrime prevention (pp. 114-143). IGI Global.
3. Aparicio-Navarro, F. J., Chadza, T. A., Kyriakopoulos, K. G., Ghafir, I., Lambotharan, S., & AsSadhan, B. (2019, February). Addressing multi-stage attacks using expert knowledge and contextual information. In 2019 22nd Conference on innovation in clouds, internet and networks and workshops (ICIN) (pp. 188-194). IEEE.
4. Bhakti, A., Sudirman, A., Sumadinata, R. W. S., & Bainus, A. (2024). State defense strategy in facing cyber threats after hacking incidents on government institutions: A case study in Indonesia. Journal of Human Security, 20(1), 109-117.
5. Bose, S., & Narayanan, A. K. (2023). Security Analysis of CMS based Websites through CMSPY. International Center For Research And Resources Development, 4(4)..
6. Elder, S., Rahman, M. R., Fringer, G., Kapoor, K., & Williams, L. (2024). A survey on software vulnerability exploitability assessment. ACM Computing Surveys, 56(8), 1-41.
7. Feutrill, A., Ranathunga, D., Yarom, Y., & Roughan, M. (2018, November). The effect of common vulnerability scoring system metrics on vulnerability exploit delay. In 2018 Sixth International Symposium on Computing and Networking (CANDAR) (pp. 1-10). IEEE.
8. Latupeirissa, J. J. P., Dewi, N. L. Y., Prayana, I. K. R., Srikandi, M. B., Ramadiansyah, S. A., & Pramana, I. B. G. A. Y. (2024). Transforming public service delivery: A comprehensive review of digitization initiatives. Sustainability, 16(7), 2818.
9. Merlang, R., & Siswanto, A. (2025). Penetration Testing System CERDAS With Brute Force Method. International Journal of Information Systems and Technology, 1(03), 104-114.
10. Mell, P., Scarfone, K., & Romanosky, S. (2006). Common vulnerability scoring system. IEEE Security & Privacy, 4(6), 85-89.
11. Milousi, K., Kiriakidis, P., Mengidis, N., Rizos, G., Mazi, M. S., Voulgaridis, A., ... & Tzovaras, D. (2024, July). Evaluating cybersecurity risk: A comprehensive comparison of vulnerability scoring methodologies. In Proceedings of the 19th international conference on availability, reliability and security (pp. 1-11).
12. Petajasoja, S., Kortti, H., Takanen, A., & Tirila, J. M. (2011, July). Ims threat and attack surface analysis using common vulnerability scoring system. In 2011 IEEE 35th annual computer software and applications conference workshops (pp. 68-73). IEEE.
13. Ribeiro, D., Fonte, V., Ramos, L. F., & Silva, J. M. (2025). Assessing the information security posture of online public services worldwide: Technical insights, trends, and policy implications. Government Information Quarterly, 42(2), 102031.
14. Salas, M. I. P., & Martins, E. (2015). A black-box approach to detect vulnerabilities in web services using penetration testing. IEEE Latin America Transactions, 13(3), 707-712.
15. Sari, D. P., & Pakaja, F. (2024). Carrying Out Website Security Analysis Using the Standard Penetration Testing Method. International Journal of Multidisciplinary Applied and Science Research, 1(01), 22-28.
16. Sarker, K. U., Yunus, F., & Deraman, A. (2023). Penetration taxonomy: A systematic review on the penetration process, framework, standards, tools, and scoring methods. Sustainability, 15(13), 10471.
17. Solikhah, M. A. (2025). Personal data protection in the era of digital transformation: Challenges and solutions in the indonesian cyber law framework. Indonesian Cyber Law Review, 2(1), 39-50.
18. Umar, R., Riadi, I., & Elfatiha, M. I. A. (2024). Security analysis of web-based academic information system using owasp framework. Kinetik: Game Technology, Information System, Computer Network, Computing, Electronics, and Control.
19. Utama, A., Khairil, K., & Supardi, R. (2025). Website Security Analysis Using Penetration Testing. International Journal of Information Systems and Technology, 1(02), 44-51.
20. Vats, P., Mandot, M., & Gosain, A. (2020, June). A comprehensive literature review of penetration testing & its applications. In 2020 8th International Conference on Reliability, Infocom Technologies and Optimization (Trends and Future Directions)(ICRITO) (pp. 674-680). IEEE.
21. Wang, Y., Yu, B., Yu, H., Xiao, L., Ji, H., & Zhao, Y. (2022). Automotive cybersecurity vulnerability assessment using the common vulnerability scoring system and Bayesian network model. IEEE Systems Journal, 17(2), 2880-2891.
22. Yamin, R. T. N., Suarjaya, I. M. A. D., & Pratama, I. P. A. E. (2022). Penetration Testing on the SISAKTI Application at Udayana University Using the OWASP Testing Guide Version 4. Jurnal Ilmiah Merpati (Menara Penelitian Akademika Teknologi Informasi), 10(3), 155.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 International Journal of Information Systems and Technology

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.

