Sep 2026· Journal of Embedded Systems, Security and Intelligent Systems· pp. 99-113· 0 citations
TL;DR
This study provides a transparent and traceable application of grey-box VAPT at the underreported faculty-subdomain level, linking reproducible technical findings with CVSS-based severity prioritization and practical cybersecurity governance implications.
Abstract
Purpose – This study evaluates the security posture of a faculty-level academic web application by applying a grey-box Vulnerability Assessment and Penetration Testing (VAPT) approach and classifying validated vulnerabilities using the Common Vulnerability Scoring System (CVSS) v3.1.
Design/methods/approach – An evaluative case study was conducted on a live Research Registration Information System using an authenticated non-administrative account. The assessment combined attack-surface mapping, automated vulnerability scanning, HTTP request–response observation, controlled request manipulation, and repeated manual validation. Each suspected vulnerability was evaluated through at least three controlled request variations and was classified as confirmed only when its behavior was reproducible, security-relevant, and distinguishable from normal application behavior or false-positive detection. Confirmed vulnerabilities were subsequently assessed using CVSS v3.1.
Findings – Automated and manual assessment produced 14 candidate findings, of which three (21.4%) were confirmed after analytical validation and 11 were rejected as non-reproducible or false positives. The validated vulnerabilities comprised SQL injection, authentication bypass, and cross-site scripting (XSS) associated with file upload functionality. All three were classified as high severity, with CVSS v3.1 base scores of 8.8, 8.3, and 7.6, respectively. The findings indicate weaknesses across backend input processing, authentication and session control, and user-generated content handling, suggesting that security risks extend across multiple operational layers of the application.
Research implications/limitations – The results demonstrate the importance of combining automated detection with manual validation to improve the reliability of web security assessments and support risk-based remediation. However, the study is limited to a single faculty-level system and a specific grey-box access context, which restricts direct generalization to other institutional architectures.
Originality/value – Rather than proposing a new security framework, this study provides a transparent and traceable application of grey-box VAPT at the underreported faculty-subdomain level, linking reproducible technical findings with CVSS-based severity prioritization and practical cybersecurity governance implications.
The study aims to integrate OWASP Top 10 categories, controlled practical testing, and CVSS-based risk assessment into a single methodological sequence and to evaluate its practical effectiveness in identifying critical web application vulnerabilities.
A comparative assessment of two Dexcom software platforms: the Dexcom Clarity web portal and the Dexcom ONE+ iPhone application is conducted, and a re-producible evaluation procedure is presented and applicable, standards-compliant mitigation recommendations for each identified issue.
A. Alshammari, Shouki A. Ebad· International Journal of Adv...· 0 citations
The findings indicate that while the OWASP Top Ten serves as a strategic reference, the WSTG is superior as a primary technical auditing framework, which enhances audit consistency, precision, and efficiency in evaluating modern web environments.
This study examined publicly disclosed Common Vulnerabilities and Exposures (CVE) records for Moodle, Chamilo, Canvas LMS, Open edX, and Sakai to assess their value for higher education security governance. A non-intrusive secondary-data audit analyzed 236 CVEs from 2018 to 3 June 2026 using platform, National Vulnerab...
Melissa T. Guillermo, Eduardo R. Yu, Reagan Ricafort· International Journal of Sci...· 0 citations
The e-commerce platform was declared sufficiently secure against direct penetration attacks on the database but remains vulnerable to end-user access manipulation, providing an objective overview of security in large-scale digital retail systems.
Sari Prabandari, Ahmad Fadilah Nur Fitrah, A. Zulfikar· IC-BESTS: International Conf...· 0 citations
It is concluded that web application security requires continuous assessment and proactive security practices throughout the software development lifecycle, and adopting OWASP guidelines and implementing effective security controls can significantly enhance the protection and resilience of modern web applications.
S. Banu, H. Shanmatha, Mehdi Gheisari et al.· BOHR International Journal o...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.