Akbar
Universitas Teknologi Akba Makassar

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

Faculty Academic Web Security Assessment via Grey-Box VAPT and CVSS v3.1 Akbar; Muh.Riyaldi Pratama; Akbar Iskandar; Riska Khaerani; Kamaruddin; Listia Utami
Journal of Embedded Systems, Security and Intelligent Systems Vol 7 No 3 (2026): September 2026
Publisher : Program Studi Teknik Komputer

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.59562/jessi.v7i3.11921

Abstract

Purpose – This study evaluates the security posture of a faculty-level academic web application by applying a grey-box Vulnerability Assessment and Penetration Testing (VAPT) approach and classifying validated vulnerabilities using the Common Vulnerability Scoring System (CVSS) v3.1. Design/methods/approach – An evaluative case study was conducted on a live Research Registration Information System using an authenticated non-administrative account. The assessment combined attack-surface mapping, automated vulnerability scanning, HTTP request–response observation, controlled request manipulation, and repeated manual validation. Each suspected vulnerability was evaluated through at least three controlled request variations and was classified as confirmed only when its behavior was reproducible, security-relevant, and distinguishable from normal application behavior or false-positive detection. Confirmed vulnerabilities were subsequently assessed using CVSS v3.1. Findings – Automated and manual assessment produced 14 candidate findings, of which three (21.4%) were confirmed after analytical validation and 11 were rejected as non-reproducible or false positives. The validated vulnerabilities comprised SQL injection, authentication bypass, and cross-site scripting (XSS) associated with file upload functionality. All three were classified as high severity, with CVSS v3.1 base scores of 8.8, 8.3, and 7.6, respectively. The findings indicate weaknesses across backend input processing, authentication and session control, and user-generated content handling, suggesting that security risks extend across multiple operational layers of the application. Research implications/limitations – The results demonstrate the importance of combining automated detection with manual validation to improve the reliability of web security assessments and support risk-based remediation. However, the study is limited to a single faculty-level system and a specific grey-box access context, which restricts direct generalization to other institutional architectures. Originality/value – Rather than proposing a new security framework, this study provides a transparent and traceable application of grey-box VAPT at the underreported faculty-subdomain level, linking reproducible technical findings with CVSS-based severity prioritization and practical cybersecurity governance implications.