Zero Entry Hacking and Common Vulnerability Scoring System (CVSS) Apisi Website

Authors

  • Subagja Wardaya UIN Syarif Hidayatullah Author

Keywords:

Information System Security, Association, Library, SLiMS, WordPress, Zero Entry Hacking

Abstract

The current development of information technology encourages non-profit organizations to utilize web-based information systems to support their public services. However, along with this utilization, the issue of information system security has become crucial due to the high frequency of cyber-attacks. This study aims to identify vulnerabilities, conduct penetration testing, and measure the level of security risk on the main portal (http://apisi.org) and library information system (http://opac.apisi.org) belonging to the Indonesian School Information Professionals Association (APISI). This experimental study applies the Zero Entry Hacking (ZEH) methodology which includes four main phases: Reconnaissance, Scanning, Exploitation, and Post-Exploitation. The results of comprehensive testing using various security audit tools detected a total of 41 vulnerabilities in the APISI information system. Based on the measurement results using the Common Vulnerability Scoring System (CVSS) v3.1 calculator, 2 vulnerabilities were found to be categorized as Critical and 9 vulnerabilities to be categorized as High. Overall, the APISI website has an average vulnerability level of 6.6 on a scale of 10, which is included in the medium risk category. The exploit successfully demonstrated the execution of a Cross-Site Scripting (XSS) attack on the OPAC and the upload of a backdoor using Weevely, which granted full control over the server directory. Recommendations included establishing a security Standard Operating Procedure (SOP) and closing the security gap by regularly updating the software version.

References

1. Althonayan, A., & Andronache, A. (2018, September). Shifting from information security towards a cybersecurity paradigm. In Proceedings of the 2018 10th International Conference on Information Management and Engineering (pp. 68-79).

2. Anchugam, C. V. (2021). Essential security elements and phases of hacking attacks. In Ethical hacking techniques and countermeasures for cybercrime prevention (pp. 114-143). IGI Global.

3. Aparicio-Navarro, F. J., Chadza, T. A., Kyriakopoulos, K. G., Ghafir, I., Lambotharan, S., & AsSadhan, B. (2019, February). Addressing multi-stage attacks using expert knowledge and contextual information. In 2019 22nd Conference on innovation in clouds, internet and networks and workshops (ICIN) (pp. 188-194). IEEE.

4. Bhakti, A., Sudirman, A., Sumadinata, R. W. S., & Bainus, A. (2024). State defense strategy in facing cyber threats after hacking incidents on government institutions: A case study in Indonesia. Journal of Human Security, 20(1), 109-117.

5. Bose, S., & Narayanan, A. K. (2023). Security Analysis of CMS based Websites through CMSPY. International Center For Research And Resources Development, 4(4)..

6. Elder, S., Rahman, M. R., Fringer, G., Kapoor, K., & Williams, L. (2024). A survey on software vulnerability exploitability assessment. ACM Computing Surveys, 56(8), 1-41.

7. Feutrill, A., Ranathunga, D., Yarom, Y., & Roughan, M. (2018, November). The effect of common vulnerability scoring system metrics on vulnerability exploit delay. In 2018 Sixth International Symposium on Computing and Networking (CANDAR) (pp. 1-10). IEEE.

8. Latupeirissa, J. J. P., Dewi, N. L. Y., Prayana, I. K. R., Srikandi, M. B., Ramadiansyah, S. A., & Pramana, I. B. G. A. Y. (2024). Transforming public service delivery: A comprehensive review of digitization initiatives. Sustainability, 16(7), 2818.

9. Merlang, R., & Siswanto, A. (2025). Penetration Testing System CERDAS With Brute Force Method. International Journal of Information Systems and Technology, 1(03), 104-114.

10. Mell, P., Scarfone, K., & Romanosky, S. (2006). Common vulnerability scoring system. IEEE Security & Privacy, 4(6), 85-89.

11. Milousi, K., Kiriakidis, P., Mengidis, N., Rizos, G., Mazi, M. S., Voulgaridis, A., ... & Tzovaras, D. (2024, July). Evaluating cybersecurity risk: A comprehensive comparison of vulnerability scoring methodologies. In Proceedings of the 19th international conference on availability, reliability and security (pp. 1-11).

12. Petajasoja, S., Kortti, H., Takanen, A., & Tirila, J. M. (2011, July). Ims threat and attack surface analysis using common vulnerability scoring system. In 2011 IEEE 35th annual computer software and applications conference workshops (pp. 68-73). IEEE.

13. Ribeiro, D., Fonte, V., Ramos, L. F., & Silva, J. M. (2025). Assessing the information security posture of online public services worldwide: Technical insights, trends, and policy implications. Government Information Quarterly, 42(2), 102031.

14. Salas, M. I. P., & Martins, E. (2015). A black-box approach to detect vulnerabilities in web services using penetration testing. IEEE Latin America Transactions, 13(3), 707-712.

15. Sari, D. P., & Pakaja, F. (2024). Carrying Out Website Security Analysis Using the Standard Penetration Testing Method. International Journal of Multidisciplinary Applied and Science Research, 1(01), 22-28.

16. Sarker, K. U., Yunus, F., & Deraman, A. (2023). Penetration taxonomy: A systematic review on the penetration process, framework, standards, tools, and scoring methods. Sustainability, 15(13), 10471.

17. Solikhah, M. A. (2025). Personal data protection in the era of digital transformation: Challenges and solutions in the indonesian cyber law framework. Indonesian Cyber Law Review, 2(1), 39-50.

18. Umar, R., Riadi, I., & Elfatiha, M. I. A. (2024). Security analysis of web-based academic information system using owasp framework. Kinetik: Game Technology, Information System, Computer Network, Computing, Electronics, and Control.

19. Utama, A., Khairil, K., & Supardi, R. (2025). Website Security Analysis Using Penetration Testing. International Journal of Information Systems and Technology, 1(02), 44-51.

20. Vats, P., Mandot, M., & Gosain, A. (2020, June). A comprehensive literature review of penetration testing & its applications. In 2020 8th International Conference on Reliability, Infocom Technologies and Optimization (Trends and Future Directions)(ICRITO) (pp. 674-680). IEEE.

21. Wang, Y., Yu, B., Yu, H., Xiao, L., Ji, H., & Zhao, Y. (2022). Automotive cybersecurity vulnerability assessment using the common vulnerability scoring system and Bayesian network model. IEEE Systems Journal, 17(2), 2880-2891.

22. Yamin, R. T. N., Suarjaya, I. M. A. D., & Pratama, I. P. A. E. (2022). Penetration Testing on the SISAKTI Application at Udayana University Using the OWASP Testing Guide Version 4. Jurnal Ilmiah Merpati (Menara Penelitian Akademika Teknologi Informasi), 10(3), 155.

Indonesia

Downloads

Published

2026-03-08

How to Cite

Zero Entry Hacking and Common Vulnerability Scoring System (CVSS) Apisi Website. (2026). International Journal of Information Systems and Technology, 2(01), 10-17. https://oneamd.com/JOL/index.php/IJOINT/article/view/110