Claim Missing Document
Check
Articles

Found 1 Documents
Search

SECURITY ANALYSIS OF A WEB-BASED ACADEMIC INFORMATION SYSTEM AT XYZ UNIVERSITY USING VULNERABILITY ASSESSMENT TECHNIQUES Faizal, Imun; Nur Isnaini, Khairunnisak; Imron, Mohammad
Multidiciplinary Output Research For Actual and International Issue (MORFAI) Vol. 5 No. 2 (2025): Multidiciplinary Output Research For Actual and International Issue
Publisher : RADJA PUBLIKA

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.54443/morfai.v5i2.3791

Abstract

This study aims to evaluate the security of a web-based academic information system at XYZ University using vulnerability assessment techniques. The system plays a vital role in supporting academic and administrative processes but stores sensitive data that makes it vulnerable to cyber threats. The research method consists of four main stages: defining the assessment scope, conducting vulnerability scanning using OWASP ZAP, analyzing the identified vulnerabilities based on type and severity using the OWASP Top Ten standard, and reporting the findings along with mitigation recommendations. The scanning results revealed 14 types of vulnerabilities, including the absence of anti-CSRF tokens, misconfigured security headers, and the use of outdated or vulnerable JavaScript libraries. Although no critical vulnerabilities were found, the identified issues still pose significant risks if left unaddressed. This study highlights the importance of regular security audits and the implementation of standardized web security practices. The proposed mitigation strategies are expected to enhance the overall cybersecurity posture of academic information systems and serve as a reference for developing more robust information security policies in higher education institutions.