The xyz.or.id website is a research institution that manages data and information. Given the importance of the data it manages, this website is vulnerable to cyber attacks, especially Cross-Site Scripting (XSS), which can pose serious risks such as data theft and user session hijacking. This study focuses on investigating the security of the input validation mechanism in the registration system. The study aims to identify and analyze security vulnerabilities on the xyz.or.id website using the black-box penetration testing method. The research method includes the stages of information gathering, penetration testing analysis, and reporting. The test results identified a total of 6 security vulnerabilities, classified into 2 high, 1 medium, and 3 low levels. The penetration test analysis found an XSS vulnerability in the “Full Name” input form on the registration page, where the injected payload was successfully executed on the client side. This finding provides empirical evidence that the input validation mechanism and website security policy are not yet optimal. This research resulted in technical recommendations for improvement, including the implementation of input validation, output encoding, and Content Security Policy (CSP) configuration to prevent exploitation by external parties.
Copyrights © 2026