Aug 2026· IC-BESTS: International Conference on Business, Economics, Technology, and Social Sciences· 0 citations
TL;DR
The e-commerce platform was declared sufficiently secure against direct penetration attacks on the database but remains vulnerable to end-user access manipulation, providing an objective overview of security in large-scale digital retail systems.
Abstract
The rapid growth of the e-commerce sector in Indonesia is directly proportional to the increasing risk of cyberattacks targeting transaction data and users' sensitive information. Large-scale e-commerce platforms with millions of active users become highly vulnerable targets if their web-based applications contain security flaws. This study aims to identify, analyze, and evaluate the risk levels of security vulnerabilities on a leading e-commerce platform in Indonesia using the Open Web Application Security Project (OWASP) framework. This research applies the Vulnerability Assessment and Penetration Testing (VAPT) method, guided by the Open Web Application Security Project (OWASP) standards. The results showed the presence of 30 alerts, including potential security vulnerabilities in the web system, whose risk levels were then classified using the Common Vulnerability Scoring System (CVSS). The e-commerce platform was declared sufficiently secure against direct penetration attacks on the database but remains vulnerable to end-user access manipulation. These findings provide an objective overview of security in large-scale digital retail systems. The implications of this research are expected to serve as technical recommendations for platform developers in mitigating and patching security flaws, as well as a theoretical reference in developing cybersecurity governance strategies within the electronic commerce ecosystem in Indonesia.
It is concluded that web application security requires continuous assessment and proactive security practices throughout the software development lifecycle, and adopting OWASP guidelines and implementing effective security controls can significantly enhance the protection and resilience of modern web applications.
S. Banu, H. Shanmatha, Mehdi Gheisari et al.· BOHR International Journal o...· 0 citations
The findings indicate that while the OWASP Top Ten serves as a strategic reference, the WSTG is superior as a primary technical auditing framework, which enhances audit consistency, precision, and efficiency in evaluating modern web environments.
The study aims to integrate OWASP Top 10 categories, controlled practical testing, and CVSS-based risk assessment into a single methodological sequence and to evaluate its practical effectiveness in identifying critical web application vulnerabilities.
A DarkWeb Monitoring Simulation platform, a web based threat intelligence concept that can analyze suspicious URLs and then create risk assessments and is a less expensive educational alternative to commercial threat intelligence solutions and still enables practical experience with cybersecurity monitoring concepts.
A. K. A. Keerthana, P. Chandana, Karbuje Sruthika· International Journal of Eme...· 0 citations
Digital transformation in the banking sector has driven an increase in the use of online banking services, but also raised the risk of cyber threats that can disrupt the confidentiality, integrity, and trustworthiness of financial transactions. This study investigates how cybersecurity, viewed from a Management Informa...
Muhammad Iffan, Vebriani Vonie Zatsiyah· Jurnal Ilmu Keuangan dan Per...· 0 citations
The increasing complexity of Information and Communication Technology (ICT) systems has created significant challenges for cybersecurity professionals in ensuring comprehensive security assessments. Traditional penetration testing methodologies (e.g., PTES, OWASP WSTG, NIST SP 800-115) often lack systematic integration...
Abdulrahman Mohammed Abdulrahman Ahmed Abutaleb· مجلة جامعة صنعاء للعلوم التط...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.