Web application security, especially on college websites, is a critical aspect in maintaining data integrity and protecting users from cyber threats. This research evaluates the security of college websites using the vulnerability assessment method. By utilizing tools such as OWASP ZAP and penetration testing techniques, this research identifies weaknesses at various security layers, including vulnerabilities to Path Traversal attacks, SQL Injection, and deficiencies in the implementation of HTTP security header settings. The analysis shows that the main vulnerabilities are caused by a lack of input validation, inadequate security configuration, and the use of outdated software libraries. This research provides practical solutions such as strengthening security configurations, system updates, and implementing modern security policies to mitigate risks. These findings aim to enhance the security of college websites and create a safer online environment.
Copyrights © 2025