Web Security Vulnerability Analysis and Mitigation Based on OWASP TOP 10

Muhammad Rizky Syarifudin, Lilik Widyawati, Ondi Asroni · Journal of Artificial Intelligence and Engineering Applications (JAIEA) · 2025

Information security is present as one of the main pillars in the challenges of the current era of technological development, especially on websites used by XYZ institutions. This study aims to test system security using penetration testing techniques with the latest standards, namely using OWASP TOP 10 in evaluating its security. The methods used in this research include scope, information gathering, vulnerability analysis, exploit, report and remediation, and testing is carried out based on the vulnerabilities obtained during vulnerability analysis according to the list of 10 types of vulnerabilities found in the OWASP Top 10 2021. The results showed that the system still has several security gaps consisting of security misconfiguration, vulnerable and outdated components, and identification and authentication failures. With appropriate improvements, the system can be more secure in the face of cyberattacks and maintain the confidentiality of mustahik data (zakat distributors). This research is expected to be a reference for system developers in improving the security of web-based applications, especially in the context of data protection.

Read the paper · More papers on PaperTik