Digital transformation is driving educational institutions to adopt web portals, yet cybersecurity evaluation is still often neglected. This study aims to identify and validate security vulnerabilities on the official website of MAN 1 Banyumas using the Penetration Testing Execution Standard (PTES) framework. Testing was conducted using a black-box penetration testing approach by combining Open Worldwide Application Security Project (OWASP ZAP) scanning and manual verification to reduce false positives. The results showed the discovery of 4 true positive vulnera-bilities, 1 false positive, and medium-risk FTP and SSH ports. Validated vulnerabilities include Cross-Site Request Forgery (CSRF), Clickjacking, session management weaknesses, and Vulnerable JS Library, while Cross-Site Scripting (XSS) vulnerabilities were confirmed as false positives. Simulation of vulnerability chaining showed that the combination of these vulnerabilities has the potential to lead to account takeover. Therefore, server hardening and JavaScript library updates are recommended to improve system security.
Copyrights © 2026