Information Technology Education Journal
Vol. 5, No. 1, February (2026)

Browser-Side Security Vulnerabilities in Healthcare Institutions Using Dynamic Application Security Testing (DAST): A Case Study of RS Mata Makassar

Supriadi Syam (Universitas Bosowa)
Abdillah SAS (Universitas Bosowa)
Sahabuddin (Universitas Bosowa)
Muh. Fadli Fauzi Sahlan (Universitas Bosowa)



Article Info

Publish Date
06 Mar 2026

Abstract

Purpose – Digital transformation has made healthcare websites critical for patient services, yet regional providers in developing economies often face a "security-functionality" paradox. This study conducts an automated vulnerability assessment of the RS Mata Makassar website to profile browser-side security and discusses how observed misconfigurations could hypothetically affect clinical operations if exploited. Design/methodology/approach – The research employs a black-box Dynamic Application Security Testing (DAST) approach using the open-source Wapiti scanner. The methodology involves crawling public endpoints and performing non-intrusive fuzzing to evaluate declarative security controls, specifically Content Security Policy (CSP), HTTP Strict Transport Security (HSTS), and secure cookie attributes. Findings – While no critical injection flaws (SQLi/XSS) were detected, the assessment revealed a complete absence of basic security controls. Compliance scores reached 0/5 for CSP, 0/5 for HSTS, and 0/3 for secure cookie attributes. These results fall significantly below global healthcare benchmarks, exposing high vulnerability to session hijacking and protocol downgrades. Originality/value – This study audits browser-side security misconfigurations, specifically CSP, HSTS, and cookie attributes using a black-box DAST approach with Wapiti on a regional healthcare website. This study provides a low-cost technical audit approach for identifying browser-side security misconfigurations in a regional healthcare website.

Copyrights © 2026






Journal Info

Abbrev

INTEC

Publisher

Subject

Computer Science & IT Education

Description

INTEC Journal is published by the Informatics and Computer Engineering Education Study Program at Makassar State University. INTEC Journal is published periodically three times a year, containing articles on research results and / or critical studies in the field of Informatics and Computer ...