Information and communication technology has increased significantly over the past few decades. Websites are often the target of cyber attacks because there are vulnerabilities that can be exploited by attackers. This study aims to conduct a Vulnerability Assessment (VA) on the website of admission of new students by following the guidelines of the Open Web Application Security Project (OWASP). OWASP provides a list of the top ten vulnerabilities that are often found in web applications, such as SQL Injection, XSS (Cross-Site Scripting), and CSRF (Cross- Site Request Forgery). This study uses the Vulnerability Assessment and Penetration Testing (VAPT) method, which consists of several stages: information gathering, scanning to identify security holes, and generating reports. The tool that used include OWASPZAP to detect and test vulnerabilities. This study produces a report that identifies 33,3% medium risk level vulnerabilities (six flags), 38% low risk level vulnerabilities (seven flags), 27,7% Informational Risk Level ( 5 flags) and no high-level vulnerabilities. It is hoped that these results can help IT staff in improving the security and convenience of accessing their pmb websites.
Copyrights © 2024