Achmad Irvan Zidny
Universitas Pamulang

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

Aplikasi Sistem Pencatatan Pengaduan Masyarakat Berbasis Standar ISO/IEC 29119:2022 Achmad Irvan Zidny; Nazilah Marzukoh Marzukoh; Chairul Anwar
Journal of Information Systems and Business Technology Vol 1 No 4 (2025): Journal of Information Systems and Business Technology
Publisher : PT Jurnal Cendekia Indonesia

Show Abstract | Download Original | Original Source | Check in Google Scholar

Abstract

The Public Complaint Recording Application is a web-based platform created using PHP Native and Bootstrap 5. This study was conducted to analyze the quality of the application through a systematic testing process in accordance with the ISO/IEC 29119:2022 standard using the Black Box Testing approach. The focus of this testing is on key features, such as authentication (registration and login), complaint data management (CRUD operations), report printing, and the application exit mechanism. Of the total 25 test scenarios evaluated, the application showed a success rate of 40%, with details of 10 successful scenarios (Pass), 14 unsuccessful scenarios (Fail), and 1 scenario appearing with a partially successful result. In addition, this study identified 10 bugs with varying levels of severity. Among these bugs, five of them are categorized as Critical because they are directly related to the system's security aspects. Critical bugs discovered include vulnerabilities to SQL Injection, XSS attacks, authorization flaws that allow unauthorized access, security holes in the file upload feature, and direct access to URLs without authentication. These findings indicate several security risks in the application that need to be addressed immediately. This study provides recommendations for improvements that should be prioritized, especially related to the implementation of input validation, session management, authorization control, and the use of prepared statements to prevent SQL Injection attacks. With improvements in these areas, it is hoped that the security, reliability, and overall quality of the application can be improved, so that the system can be used safely and effectively by the public.