JOURNAL OF APPLIED INFORMATICS AND COMPUTING
Vol. 10 No. 3 (2026): June 2026

Identification and Mitigation of Web Application Vulnerabilities in Healthcare Systems

Saeful Diyan Pratama (Universitas PGRI Semarang)
Aris Tri Joko Harjanto (Universitas PGRI Semarang)
Bambang Agus Herlambang (Universitas PGRI Semarang)



Article Info

Publish Date
14 Jun 2026

Abstract

The rapid adoption of web-based applications in healthcare systems has increased exposure to security threats, particularly at the application layer. Despite the implementation of various security mechanisms, many systems remain vulnerable due to improper input validation, weak authentication controls, and insecure database interactions. This study aims to identify, validate, and mitigate critical web application vulnerabilities in a healthcare system, focusing on nonce reuse vulnerabilities in token-based authentication mechanisms, stored cross-site scripting (XSS), and SQL injection. The research employs an empirical approach through controlled security testing, including vulnerability identification, exploitation validation, and mitigation evaluation. The results demonstrate that all identified vulnerabilities are actively exploitable, affecting authentication integrity, data confidentiality, and system reliability. Furthermore, the implementation of targeted mitigation strategies, such as token validation, input sanitization, and parameterized queries, substantially reduced the observed exploitability of the identified vulnerabilities within the tested scenarios. These findings highlight that application-layer security weaknesses remain a significant risk in healthcare systems and require systematic and integrated mitigation approaches. The study suggests that adopting secure-by-design principles and continuous security testing may improve system resilience against application-layer attacks. The implications of this research emphasize the need for proactive security practices in web-based healthcare applications to prevent exploitation and protect sensitive data from evolving cyber threats.

Copyrights © 2026






Journal Info

Abbrev

JAIC

Publisher

Subject

Computer Science & IT

Description

Journal of Applied Informatics and Computing (JAIC) Volume 2, Nomor 1, Juli 2018. Berisi tulisan yang diangkat dari hasil penelitian di bidang Teknologi Informatika dan Komputer Terapan dengan e-ISSN: 2548-9828. Terdapat 3 artikel yang telah ditelaah secara substansial oleh tim editorial dan ...