The use of web-based information systems in higher education institutions, particularly e-journal platforms, continues to rise. However, this is often not accompanied by adequate security measures, thereby threatening Confidentiality, Integrity, and Availability (CIA). This study aims to evaluate the security of a proceedings system based on Open Journal Systems (OJS) at the Adisutjipto Institute of Aeronautical Technology (ITDA) in Yogyakarta. The method used was penetration testing based on the NIST SP 800-115 standard via a black-box approach, which included the planning, discovery, attack, and reporting phases. Initial identification using the OWASP ZAP automated scanner identified 11 vulnerability indicators with estimated severity levels ranging from low to medium. However, after conducting the exploitation validation (proof-of-concept) phase and assessment using the OWASP Risk Rating method, it was found that some vulnerabilities posed a higher risk impact than the initial scan results indicated. The final research results confirmed the presence of 3 high-risk findings and 1 medium-risk finding. These high-risk vulnerabilities include Host Header Injection, which enables Reflected XSS attacks; a Security Misconfiguration on the /server-status endpoint; and the absence of a rate-limiting mechanism in the authentication feature. This study concludes that the system has significant security vulnerabilities that require immediate mitigation. Key recommendations include updating the OJS platform version, implementing server configuration hardening, and enhancing login security mechanisms to continuously protect the Integrity and Confidentiality of the institution’s academic data.
Copyrights © 2026