Bulletin of Computer Science Research
Vol. 6 No. 4 (2026): June 2026

Security Assessment of E-Commerce Website Using NIST SP 800-115 Based on OWASP Top 10

Arif Setyo Wibowo (Universitas Pembangunan Nasional "Veteran" Jawa Timur, Surabaya)
Henni Endah Wahanani (Universitas Pembangunan Nasional "Veteran" Jawa Timur, Surabaya)
Andreas Nugroho Sihananto (Universitas Pembangunan Nasional "Veteran" Jawa Timur, Surabaya)



Article Info

Publish Date
30 Jun 2026

Abstract

The rapid growth of e-commerce platforms in Indonesia has increased the risk of cyber threats targeting sensitive user data, including personal information and payment details. PT. XYZ, a mattress company that recently launched its first e-commerce website, has attracted 42,222 visitors and generated revenue of Rp994,878,300 within its first six months, yet has never undergone any form of security testing. This raises serious concerns, as undetected vulnerabilities may expose the platform to identity theft, data breaches, and unauthorized access. This study aims to identify existing security vulnerabilities, determine the severity level of each finding, and provide concrete remediation recommendations before those vulnerabilities are exploited. The assessment was conducted using the NIST SP 800-115 framework across four phases: Planning, Discovery, Attack, and Reporting, with vulnerability classification based on OWASP Top 10 (2021). The Discovery phase utilized Google Dorking, WHOIS, wfuzz, Wappalyzer, Nmap, Burp Suite, and OWASP ZAP to gather intelligence and identify weaknesses. The Attack phase successfully exploited six confirmed vulnerabilities: Clickjacking, CSP Header Not Set, Vulnerable JS Library, Cross-Domain Misconfiguration, Source Code Disclosure, and Username Enumeration and Brute Force, mapped to OWASP categories A05, A06, and A07, with risk levels ranging from Medium to High. This research contributes by demonstrating that newly deployed platforms are not inherently secure and that integrating NIST SP 800-115 with OWASP Top 10 provides a structured approach to identifying real security vulnerabilities in e-commerce systems.

Copyrights © 2026






Journal Info

Abbrev

bulletincsr

Publisher

Subject

Computer Science & IT

Description

Bulletin of Computer Science Research covers the whole spectrum of Computer Science, which includes, but is not limited to : • Artificial Immune Systems, Ant Colonies, and Swarm Intelligence • Bayesian Networks and Probabilistic Reasoning • Biologically Inspired Intelligence • Brain-Computer ...