Evaluating the security of web-based academic information systems has become crucial as cyber threats in higher education environments increase. The track record of security incidents in information systems at UIN Sultan Syarif Kasim Riau has prompted an urgent need for preventative action; therefore, the website https://seminar-fst.uin-suska.ac.id, as an active academic service that stores sensitive data, requires a proactive evaluation. Testing used a black-box testing approach through four phases: planning, discovery, attack, and reporting. The results revealed a critical vulnerability in the form of SQL injection in URL parameters, which allows unauthorized database enumeration (MariaDB), thus threatening data confidentiality and integrity. Additionally, medium-level vulnerabilities were discovered, such as the use of an outdated JavaScript library (Moment.js 2.8.1) and misconfiguration of HTTP security headers, including the absence of a Content Security Policy (CSP) and an Anti-CSRF mechanism. Recommendations include prepared statements, strict input validation, updating dependencies, and strengthening security configurations.
Copyrights © 2026