Skip to content
Open access

Faculty Academic Web Security Assessment via Grey-Box VAPT and CVSS v3.1

Sep 2026 · Journal of Embedded Systems, Security and Intelligent Systems · pp. 99-113 · 0 citations

TL;DR

This study provides a transparent and traceable application of grey-box VAPT at the underreported faculty-subdomain level, linking reproducible technical findings with CVSS-based severity prioritization and practical cybersecurity governance implications.

Abstract

Purpose – This study evaluates the security posture of a faculty-level academic web application by applying a grey-box Vulnerability Assessment and Penetration Testing (VAPT) approach and classifying validated vulnerabilities using the Common Vulnerability Scoring System (CVSS) v3.1. Design/methods/approach – An evaluative case study was conducted on a live Research Registration Information System using an authenticated non-administrative account. The assessment combined attack-surface mapping, automated vulnerability scanning, HTTP request–response observation, controlled request manipulation, and repeated manual validation. Each suspected vulnerability was evaluated through at least three controlled request variations and was classified as confirmed only when its behavior was reproducible, security-relevant, and distinguishable from normal application behavior or false-positive detection. Confirmed vulnerabilities were subsequently assessed using CVSS v3.1. Findings – Automated and manual assessment produced 14 candidate findings, of which three (21.4%) were confirmed after analytical validation and 11 were rejected as non-reproducible or false positives. The validated vulnerabilities comprised SQL injection, authentication bypass, and cross-site scripting (XSS) associated with file upload functionality. All three were classified as high severity, with CVSS v3.1 base scores of 8.8, 8.3, and 7.6, respectively. The findings indicate weaknesses across backend input processing, authentication and session control, and user-generated content handling, suggesting that security risks extend across multiple operational layers of the application. Research implications/limitations – The results demonstrate the importance of combining automated detection with manual validation to improve the reliability of web security assessments and support risk-based remediation. However, the study is limited to a single faculty-level system and a specific grey-box access context, which restricts direct generalization to other institutional architectures. Originality/value – Rather than proposing a new security framework, this study provides a transparent and traceable application of grey-box VAPT at the underreported faculty-subdomain level, linking reproducible technical findings with CVSS-based severity prioritization and practical cybersecurity governance implications.

Read PDF

Similar papers

TOP 10

The study aims to integrate OWASP Top 10 categories, controlled practical testing, and CVSS-based risk assessment into a single methodological sequence and to evaluate its practical effectiveness in identifying critical web application vulnerabilities.

Nuriddinova Dilnura, Samarov Sherzod, Hamrayevich · 0 citations
Open access 2026

Black-Box Cybersecurity Assessment of Software as a Medical Device (SaMD): A Case Study

A comparative assessment of two Dexcom software platforms: the Dexcom Clarity web portal and the Dexcom ONE+ iPhone application is conducted, and a re-producible evaluation procedure is presented and applicable, standards-compliant mitigation recommendations for each identified issue.

A. Alshammari, Shouki A. Ebad · 0 citations
Open access Aug 2026

Comparative Effectiveness of OWASP WSTG and Top Ten in Web Security Audits

The findings indicate that while the OWASP Top Ten serves as a strategic reference, the WSTG is superior as a primary technical auditing framework, which enhances audit consistency, precision, and efficiency in evaluating modern web environments.

Moch Wahyu Sampurno Utomo, H. Wahanani, Achmad Junaidi · 0 citations
Review Open access Sep 2026

CVE-based security audit of open-source learning management systems in higher education using CVSS and OWASP

This study examined publicly disclosed Common Vulnerabilities and Exposures (CVE) records for Moodle, Chamilo, Canvas LMS, Open edX, and Sakai to assess their value for higher education security governance. A non-intrusive secondary-data audit analyzed 236 CVEs from 2018 to 3 June 2026 using platform, National Vulnerab...

Melissa T. Guillermo, Eduardo R. Yu, Reagan Ricafort · 0 citations
Conference Open access Aug 2026

ANALYSIS OF SECURITY VULNERABILITY LEADING E-COMMERCE PLATFORMS USING OWASP

The e-commerce platform was declared sufficiently secure against direct penetration attacks on the database but remains vulnerable to end-user access manipulation, providing an objective overview of security in large-scale digital retail systems.

Sari Prabandari, Ahmad Fadilah Nur Fitrah, A. Zulfikar · 0 citations
Open access 2026

Web application security using top 10 OWASP

It is concluded that web application security requires continuous assessment and proactive security practices throughout the software development lifecycle, and adopting OWASP guidelines and implementing effective security controls can significantly enhance the protection and resilience of modern web applications.

S. Banu, H. Shanmatha, Mehdi Gheisari et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.