The implementation of Electronic-Based Government Systems (SPBE) increases the dependence of public services on web applications, making application security an essential aspect of digital governance. This study was conducted to identify, classify, and provide mitigation recommendations for security vulnerabilities in two public web applications managed in the Cimahi City government environment, namely XYZ Regional Office Application and XYZ Subdistrict Website. The research used a non-disruptive Vulnerability Assessment approach based on the Open Worldwide Application Security Project (OWASP) Top 10 framework, supported by OWASP Zed Attack Proxy (ZAP), Burp Suite Pro, and manual validation of request-response evidence. The assessment identified 24 valid findings, consisting of 6 Medium, 11 Low, and 7 Informational findings. The dominant vulnerability category was A05: Security Misconfiguration, including missing security headers, server information disclosure, weak cookie attributes, and incomplete transport security configuration. XYZ Regional Office Application became the main mitigation priority because its login form still used HTTP. These findings highlight the need for HTTPS enforcement, HSTS activation, CSP implementation, cookie hardening, outdated component updates, and periodic security assessment.
Copyrights © 2026