ANALISIS KERENTANAN KEAMANAN WEBSITE PERGURUAN TINGGI TERHADAP SERANGAN WEB DEFACEMENT BERDASARKAN KERANGKA KERJA OWASP TOP 10 DAN COMMON VULNERABILITY SCORING SYSTEM (CVSS)
Abstract
The widespread cybersecurity attacks involving web defacement for embedding illicit online gambling advertisements across higher education institution domains (.ac.id) pose critical risks to academic reputation and data integrity. This study evaluates university web application vulnerability postures against web defacement by integrating the OWASP Top 10 framework and the Common Vulnerability Scoring System (CVSS v3.1). The research adopts an empirical security assessment methodology comprising automated vulnerability discovery and controlled penetration testing. Results reveal critical exposure dominated by OWASP A01 (Broken Access Control) scoring CVSS 8.8 (High) and A03 (Injection) scoring CVSS 9.8 (Critical), which grant adversaries unauthorized privileges to inject malicious gambling landing pages. A comprehensive multi-layered defense strategy is formulated, encompassing Web Application Firewall (WAF) deployment, routine CMS/OJS patching, strict upload directory privilege controls, and proactive File Integrity Monitoring (FIM).