<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v2.3 20070202//EN" "journalpublishing.dtd">
<article xml:lang="EN" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" article-type="research-article">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">Bohr. Scit.</journal-id>
<journal-title>BOHR International Journal of Smart Computing and Information Technology</journal-title>
<abbrev-journal-title abbrev-type="pubmed">Bohr. Scit.</abbrev-journal-title>
<issn pub-type="epub">2583-2026</issn>
<publisher>
<publisher-name>BOHR</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="doi">10.54646/bijscit.2026.53</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Research</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Web application security using top 10 OWASP</article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author" corresp="yes">
<name><surname>Banu</surname> <given-names>Sabitha</given-names></name>
<xref ref-type="aff" rid="aff1"><sup>1</sup></xref>
<xref ref-type="corresp" rid="c001"><sup>&#x002A;</sup></xref>
</contrib>
<contrib contrib-type="author">
<name><surname>Shanmatha</surname> <given-names>H.</given-names></name>
<xref ref-type="aff" rid="aff1"><sup>1</sup></xref>
</contrib>
<contrib contrib-type="author">
<name><surname>Gheisari</surname> <given-names>Mehdi</given-names></name>
<xref ref-type="aff" rid="aff2"><sup>2</sup></xref>
<xref ref-type="aff" rid="aff3"><sup>3</sup></xref>
<xref ref-type="aff" rid="aff4"><sup>4</sup></xref>
<xref ref-type="aff" rid="aff5"><sup>5</sup></xref>
</contrib>
<contrib contrib-type="author">
<name><surname>Pingmei</surname> <given-names>Zhou</given-names></name>
<xref ref-type="aff" rid="aff4"><sup>4</sup></xref>
</contrib>
<contrib contrib-type="author">
<name><surname>Akhtari</surname> <given-names>Hossein</given-names></name>
<xref ref-type="aff" rid="aff6"><sup>6</sup></xref>
</contrib>
<contrib contrib-type="author">
<name><surname>Dashti</surname> <given-names>Sajad</given-names></name>
<xref ref-type="aff" rid="aff7"><sup>7</sup></xref>
</contrib>
<contrib contrib-type="author">
<name><surname>Meimouneh</surname> <given-names>Seyed Kazem Gheblezadeh</given-names></name>
<xref ref-type="aff" rid="aff8"><sup>8</sup></xref>
</contrib>
</contrib-group>
<aff id="aff1"><sup>1</sup><institution>Department of Computer Science with Cybersecurity, PSGR Krishnammal College for Women</institution>, <addr-line>Coimbatore</addr-line>, <country>India</country></aff>
<aff id="aff2"><sup>2</sup><institution>Institute of Artificial Intelligence, Shaoxing University</institution>, <addr-line>Zhejiang</addr-line>, <country>China</country></aff>
<aff id="aff3"><sup>3</sup><institution>Department of Computer Science and Engineering, Saveetha School of Engineering, Saveetha Institute of Medical and Technical Science</institution>, <addr-line>Chennai</addr-line>, <country>India</country></aff>
<aff id="aff4"><sup>4</sup><institution>Department of R&#x0026;D, Shenzhen BKD Co LTD</institution>, <addr-line>Shenzhen</addr-line>, <country>China</country></aff>
<aff id="aff5"><sup>5</sup><institution>Department of Computer Engineering, Shi.C., Islamic Azad University</institution>, <addr-line>Shiraz</addr-line>, <country>Iran</country></aff>
<aff id="aff6"><sup>6</sup><institution>Department of Electrical Engineering, Kazeroon Branch, Islamic Azad University</institution>, <addr-line>Fars</addr-line>, <country>Iran</country></aff>
<aff id="aff7"><sup>7</sup><institution>Islamic Azad University, Bandargaz Branch</institution>, <addr-line>Bandar Abbas</addr-line>, <country>Iran</country></aff>
<aff id="aff8"><sup>8</sup><institution>Department of Computer Science, Meybod, Islamic Azad University</institution>, <addr-line>Meybod</addr-line>, <country>Iran</country></aff>
<author-notes>
<corresp id="c001">&#x002A;Correspondence: Sabitha Banu, <email>sabithabanu@psgrkcw.ac.in</email></corresp>
</author-notes>
<pub-date pub-type="epub">
<day>31</day>
<month>07</month>
<year>2026</year>
</pub-date>
<volume>7</volume>
<issue>1</issue>
<fpage>29</fpage>
<lpage>40</lpage>
<history>
<date date-type="received">
<day>04</day>
<month>05</month>
<year>2026</year>
</date>
<date date-type="accepted">
<day>28</day>
<month>06</month>
<year>2026</year>
</date>
</history>
<permissions>
<copyright-statement>Copyright &#x00A9; 2026 Banu, Shanmatha, Gheisari, Pingmei, Akhtari, Dashti and Meimouneh.</copyright-statement>
<copyright-year>2026</copyright-year>
<copyright-holder>Banu, Shanmatha, Gheisari, Pingmei, Akhtari, Dashti and Meimouneh</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/"><p>&#x00A9; The Author(s). 2024 Open Access This article is distributed under the terms of the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/), which permits unrestricted use, distribution, and reproduction in any medium, provided you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons license, and indicate if changes were made.</p></license>
</permissions>
<abstract>
<p>Web applications have become an integral part of everyday life, enabling services such as online banking, e-commerce, education, and communication. As their adoption continues to increase, so does the risk of cyberattacks targeting security weaknesses within these applications. Many of these vulnerabilities arise from insecure coding practices, improper configurations, and inadequate security controls. To address these challenges, the Open Web Application Security Project (OWASP) Top 10 serves as a widely accepted framework for identifying and mitigating common web application security risks. This study investigates web application vulnerabilities based on the OWASP Top 10 framework through a practical security assessment approach. Various security tools, including Burp Suite, OWASP ZAP, Threat Dragon, Hydra, Trivy, and Splunk, were utilized to perform threat modeling, vulnerability assessment, authentication testing, dependency analysis, and security monitoring. Testing was conducted in a controlled environment to evaluate the effectiveness of these tools in identifying security weaknesses. The assessment revealed several significant vulnerabilities, including Broken Access Control (IDOR), Cryptographic Failures, HTML Injection, Insecure Design, Identification and Authentication Failures, and Security Logging and Monitoring Failures. The findings demonstrate how these weaknesses can compromise application security and expose systems to potential attacks. Appropriate mitigation measures were also identified to reduce associated risks. The study concludes that web application security requires continuous assessment and proactive security practices throughout the software development lifecycle. Adopting OWASP guidelines and implementing effective security controls can significantly enhance the protection and resilience of modern web applications.</p>
</abstract>
<kwd-group>
<kwd>web application security</kwd>
<kwd>OWASP top 10</kwd>
<kwd>vulnerability assessment</kwd>
<kwd>penetration testing</kwd>
<kwd>burp suite</kwd>
<kwd>OWASP ZAP</kwd>
<kwd>threat modeling</kwd>
<kwd>security monitoring</kwd>
</kwd-group>
<counts>
<fig-count count="23"/>
<table-count count="0"/>
<equation-count count="0"/>
<ref-count count="27"/>
<page-count count="12"/>
<word-count count="3715"/>
</counts>
</article-meta>
</front>
<body>
<sec id="S1" sec-type="intro">
<title>Introduction</title>
<p>Web applications are widely used in everyday activities such as online banking, e-commerce, education, and social networking. As these applications handle large amounts of sensitive information, ensuring their security has become increasingly important. However, vulnerabilities caused by insecure coding practices, weak authentication mechanisms, improper input validation, and misconfigurations can expose applications to cyberattacks.</p>
<p>The Open Web Application Security Project (OWASP) Top 10 provides a globally recognized framework that identifies the most critical security risks affecting web applications. It serves as a valuable guideline for developers and security professionals to understand, detect, and mitigate common vulnerabilities.</p>
<p>This study focuses on evaluating web application security using the OWASP Top 10 framework. Practical testing was conducted in a vulnerable web application environment to identify and analyze common security issues, including Broken Access Control, Cryptographic Failures, HTML Injection, Insecure Design, Authentication Failures, and Security Logging and Monitoring Failures. The findings highlight the importance of secure development practices and effective security testing in protecting modern web applications.</p>
<sec id="S1.SS1">
<title>Literature survey</title>
<p>Widyawati et al. (<xref ref-type="bibr" rid="B1">1</xref>) presented a study titled &#x201C;Web Security Vulnerability Analysis and Mitigation Based on OWASP Top 10,&#x201D; published in the Journal of Artificial Intelligence and Engineering Applications (JAIEA). This work provides a detailed analysis of common web application vulnerabilities based on the OWASP Top 10 framework and discusses effective mitigation strategies with a focus on modern web applications.</p>
<p>Li and Li (<xref ref-type="bibr" rid="B2">2</xref>) proposed a paper entitled &#x201C;Evolution of Application Security based on OWASP Top 10 and CWE/SANS Top 25 with Predictions for the 2025 OWASP Top 10,&#x201D; presented at the ICICT 2025 Conference. The study analyzes the evolution of application security threats over time and predicts future OWASP risks by comparing OWASP Top 10 vulnerabilities with CWE/SANS Top 25 attack patterns.</p>
<p>Patil et al. (<xref ref-type="bibr" rid="B3">3</xref>) published a review paper titled &#x201C;A Review of the OWASP Top 10 Web Application Security Risks and Best Practices&#x201D; in the ICCUBEA 2023 Conference. This work offers a comprehensive review of OWASP Top 10 security risks and highlights best practice mitigation techniques that can be adopted to ensure secure web application development.</p>
<p>Rohmaniah et al. (<xref ref-type="bibr" rid="B4">4</xref>) presented the study &#x201C;Enhancing Website Security Using VAPT Based on OWASP Top Ten,&#x201D; published in the Journal of Applied Informatics and Computing. This research demonstrates how vulnerability assessment and penetration testing (VAPT) techniques based on OWASP Top 10 can improve the resilience and security posture of modern web applications.</p>
<p>Qadir et al. (<xref ref-type="bibr" rid="B5">5</xref>) proposed &#x201C;Comparative Evaluation of Approaches &#x0026; Tools for Security Testing of Web Applications,&#x201D; published in PeerJ Computer Science. The paper compares different security testing tools and methodologies aligned with OWASP, highlighting their effectiveness in detecting vulnerabilities across diverse web applications.</p>
<p>Fredj et al. (<xref ref-type="bibr" rid="B6">6</xref>) conducted a study titled &#x201C;An OWASP Top Ten Driven Survey on Web Application Protection Methods,&#x201D; available on TechRxiv. This work surveys various protection mechanisms adopted to secure web applications from OWASP Top 10 vulnerabilities, providing an overview of preventive strategies and best practices.</p>
<p>Kumar and Rani (<xref ref-type="bibr" rid="B7">7</xref>) published &#x201C;Implementation and Analysis of Web Application Security Measures using OWASP Guidelines&#x201D; in the ICMACC 2022 Conference. The study focuses on the practical implementation of OWASP security measures and analyzes their performance, offering insights into effective mitigation strategies for real-world web applications.</p>
<p>Nawrocki and Ko&#x0142;odziej (<xref ref-type="bibr" rid="B8">8</xref>) conducted a study titled &#x201C;Vulnerabilities of Web Applications: Good Practices and New Trends,&#x201D; published in Applied Cybersecurity &#x0026; Internet Governance. This work discusses modern web vulnerabilities and emerging cybersecurity trends with OWASP alignment.</p>
<p>Nedeljkovi&#x0107; et al. (<xref ref-type="bibr" rid="B9">9</xref>) conducted a study titled &#x201C;Use of OWASP Top 10 in Web Application Security,&#x201D; published in ITEMA 2020. This work explains the importance of OWASP guidelines in strengthening web application security.</p>
<p>Lala et al. (<xref ref-type="bibr" rid="B10">10</xref>) conducted a study titled &#x201C;Secure Web Development using OWASP Guidelines,&#x201D; published in ICICCS 2021. This work focuses on secure coding techniques and development practices using OWASP principles.</p>
</sec>
</sec>
<sec id="S2">
<title>Methodology</title>
<p>The experiments and security assessments were conducted from November 2025 to March 2026 in a controlled laboratory environment (<xref ref-type="bibr" rid="B11">11</xref>&#x2013;<xref ref-type="bibr" rid="B27">27</xref>).</p>
<sec id="S2.SS1">
<title>Test environment</title>
<p>The security assessment was conducted in a controlled laboratory environment using Kali Linux 2025.4 as the primary operating system. The tools used during the assessment included Burp Suite Community Edition, OWASP ZAP 2.16, Hydra 9.5, OWASP Threat Dragon 2.x, Splunk Enterprise 9.x, and Trivy 0.61. The target applications selected for testing were Damn Vulnerable Web Application (DVWA), Buggy Web Application (bWAPP), and OWASP Mutillidae. These applications were chosen because they intentionally contain vulnerabilities representing different categories of the OWASP Top 10, enabling comprehensive security testing and analysis.</p>
<p>The methodology adopted in this research follows a systematic and tool-driven approach to assess the security of web applications in alignment with the OWASP Top 10 vulnerabilities. Three intentionally vulnerable web applications, namely DVWA, bWAPP, and Mutillidae, were selected as the target environments because each application demonstrates different categories of OWASP Top 10 vulnerabilities. Using multiple applications enabled broader coverage of attack scenarios than relying on a single testing platform. DVWA was primarily used for authentication and access control testing, bWAPP for business logic and parameter tampering assessments, and Mutillidae for evaluating injection-related vulnerabilities. Initially, threat modeling was performed using OWASP Threat Dragon to identify potential attack surfaces, trust boundaries, and high-risk components within the application architecture. Based on the identified threats, dynamic application security testing was carried out using Burp Suite and OWASP ZAP to detect vulnerabilities such as injection flaws, cross-site scripting, insecure authentication mechanisms, and security misconfigurations. To strengthen the assessment, Trivy was used to scan application dependencies and configurations for known vulnerabilities, providing insight into risks arising from outdated or insecure components. Authentication security was further evaluated using Hydra through controlled brute-force testing to analyze the resilience of login mechanisms. In addition to vulnerability detection, Splunk was deployed to collect and analyze logs generated during testing, enabling real-time monitoring of security events and suspicious activities. The combined use of these tools allowed for comprehensive vulnerability identification, correlation of security findings, and validation of attack scenarios, thereby ensuring a practical and effective evaluation of web application security. Furthermore, the findings obtained from each tool were cross-verified to reduce false positives and ensure the accuracy of the identified vulnerabilities.</p>
</sec>
<sec id="S2.SS2">
<title>False positive validation</title>
<p>To improve the accuracy of the vulnerability assessment, all findings generated by security tools were manually verified before inclusion in the final results. Vulnerabilities identified by OWASP ZAP were cross-checked using Burp Suite and additional manual testing. Findings that could not be reproduced or validated during testing were classified as false positives and excluded from the final analysis. This validation process helped ensure the accuracy, reliability, and consistency of the reported security findings.</p>
</sec>
</sec>
<sec id="S3">
<title>Results or finding</title>
<sec id="S3.SS1">
<title>Broken access control ticket price (IDOR)</title>
<p>Refer to <xref ref-type="fig" rid="F1">Figures 1</xref>&#x2013;<xref ref-type="fig" rid="F4">4</xref> for additional information.</p>
<fig id="F1" position="float">
<label>FIGURE 1</label>
<caption><p>Ordered 10 Tickets in bWAPP website at 150 EUR.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g001.tif"/>
</fig>
<fig id="F2" position="float">
<label>FIGURE 2</label>
<caption><p>Captured the request using OWASP ZAP.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g002.tif"/>
</fig>
<fig id="F3" position="float">
<label>FIGURE 3</label>
<caption><p>Modified the captured request of ticket price from 15 EUR to 1 EUR.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g003.tif"/>
</fig>
<fig id="F4" position="float">
<label>FIGURE 4</label>
<caption><p>The price of 15 tickets has been tampered from 150 EUR to 10 EUR.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g004.tif"/>
</fig>
<sec id="S3.SS1.SSS1">
<title>Recommended fix</title>
<p>Use Authorizations in the Server-side code for all requests to check the authorization of users before using any resources. Always use the principle of least privilege and review the access control policy periodically.</p>
</sec>
</sec>
<sec id="S3.SS2">
<title>Cryptographic failure</title>
<p>Refer to <xref ref-type="fig" rid="F5">Figures 5</xref> and <xref ref-type="fig" rid="F6">6</xref> for additional information.</p>
<fig id="F5" position="float">
<label>FIGURE 5</label>
<caption><p>Entering username and password, capturing the request in Burp Suite.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g005.tif"/>
</fig>
<fig id="F6" position="float">
<label>FIGURE 6</label>
<caption><p>The username and password are in plain text.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g006.tif"/>
</fig>
<sec id="S3.SS2.SSS1">
<title>Recommended fix</title>
<p>Use HTTPS with TLS 1.2 or higher for all communications, encrypt sensitive data at rest, and avoid storing passwords in plain text. Strong cryptographic algorithms should be used for data protection.</p>
</sec>
</sec>
<sec id="S3.SS3">
<title>HTML injection</title>
<p>Refer to <xref ref-type="fig" rid="F7">Figures 7</xref>&#x2013;<xref ref-type="fig" rid="F10">10</xref> for additional information.</p>
<fig id="F7" position="float">
<label>FIGURE 7</label>
<caption><p>Accessing the Mutillidae website and viewing browser info.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g007.tif"/>
</fig>
<fig id="F8" position="float">
<label>FIGURE 8</label>
<caption><p>User agent contains browser information.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g008.tif"/>
</fig>
<fig id="F9" position="float">
<label>FIGURE 9</label>
<caption><p>Changing user-agent details by performing HTML injection using Burp Suite.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g009.tif"/>
</fig>
<fig id="F10" position="float">
<label>FIGURE 10</label>
<caption><p>The user agent has been modified as test.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g010.tif"/>
</fig>
<sec id="S3.SS3.SSS1">
<title>Recommended fix</title>
<p>Implement input validation and output sanitization, use parameterized queries or prepared statements, and avoid dynamically constructing structured query language (SQL) queries using user-supplied data.</p>
</sec>
</sec>
<sec id="S3.SS4">
<title>Insecure design</title>
<p>Refer to <xref ref-type="fig" rid="F11">Figures 11</xref> and <xref ref-type="fig" rid="F12">12</xref> for additional information.</p>
<fig id="F11" position="float">
<label>FIGURE 11</label>
<caption><p>Creating a threat model in OWASP Threat Dragon.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g011.tif"/>
</fig>
<fig id="F12" position="float">
<label>FIGURE 12</label>
<caption><p>Identifying and analyzing security threats.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g012.tif"/>
</fig>
<sec id="S3.SS4.SSS1">
<title>Recommended fix</title>
<p>Apply secure design principles, perform threat modeling during development, and conduct regular security reviews to identify and mitigate risks before deployment.</p>
</sec>
</sec>
<sec id="S3.SS5">
<title>Security misconfiguration</title>
<p>Refer to <xref ref-type="fig" rid="F13">Figures 13</xref> and <xref ref-type="fig" rid="F14">14</xref> for additional information.</p>
<fig id="F13" position="float">
<label>FIGURE 13</label>
<caption><p>Creating a threat model in OWASP Threat Dragon.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g013.tif"/>
</fig>
<fig id="F14" position="float">
<label>FIGURE 14</label>
<caption><p>Trivy vulnerability report summary.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g014.tif"/>
</fig>
<sec id="S3.SS5.SSS1">
<title>Recommended fix</title>
<p>Implement secure configuration settings for servers, applications, databases, and network components. Remove unnecessary services, default accounts, and unused features, regularly apply security patches and updates, enforce proper access controls, and conduct periodic configuration reviews and vulnerability assessments to identify and remediate misconfigurations.</p>
</sec>
</sec>
<sec id="S3.SS6">
<title>Identification and authentication failure</title>
<p>Refer to <xref ref-type="fig" rid="F15">Figures 15</xref> and <xref ref-type="fig" rid="F16">16</xref> for additional information.</p>
<fig id="F15" position="float">
<label>FIGURE 15</label>
<caption><p>Performing a brute force attack using Hydra.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g015.tif"/>
</fig>
<fig id="F16" position="float">
<label>FIGURE 16</label>
<caption><p>Successful login using cracked credentials.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g016.tif"/>
</fig>
<sec id="S3.SS6.SSS1">
<title>Recommended fix</title>
<p>Implement strong authentication mechanisms by enforcing complex password policies, enabling multi-factor authentication (MFA), and applying account lockout controls to prevent brute-force attacks. Use secure password storage techniques such as hashing with strong algorithms, manage user sessions securely, and regularly monitor authentication logs for suspicious activities.</p>
</sec>
</sec>
<sec id="S3.SS7">
<title>Cross-site request forgery (CSRF)</title>
<p>Refer to <xref ref-type="fig" rid="F17">Figures 17</xref> and <xref ref-type="fig" rid="F18">18</xref> for additional information.</p>
<fig id="F17" position="float">
<label>FIGURE 17</label>
<caption><p>Accessing a cross-site request forgery (CSRF)-vulnerable password change page.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g017.tif"/>
</fig>
<fig id="F18" position="float">
<label>FIGURE 18</label>
<caption><p>Executing CSRF attack and changing password.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g018.tif"/>
</fig>
<sec id="S3.SS7.SSS1">
<title>Recommended fix</title>
<p>Implement anti-cross-site request forgery (CSRF) tokens for all state-changing requests and validate them on the server side. Configure cookies with the Same Site attribute (Strict or Lax) to prevent unauthorized cross-site requests. Require re-authentication or MFA for sensitive actions and validate the Origin and Referrer headers where applicable. Conduct regular security testing to ensure CSRF protections remain effective.</p>
</sec>
</sec>
<sec id="S3.SS8">
<title>Security logging and monitoring failures</title>
<p>Refer to <xref ref-type="fig" rid="F19">Figures 19</xref> and <xref ref-type="fig" rid="F20">20</xref> for additional information.</p>
<fig id="F19" position="float">
<label>FIGURE 19</label>
<caption><p>Log collection and forwarding to Splunk.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g019.tif"/>
</fig>
<sec id="S3.SS8.SSS1">
<title>Query used</title>
<p>index=apache_logs</p>
<p>&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;| stats count by clientip</p>
<p>&#x00A0;&#x00A0;&#x00A0;&#x00A0;&#x00A0;| where count &#x003E; 10</p>
</sec>
<sec id="S3.SS8.SSS2">
<title>Observation</title>
<p>The query identified IP addresses generating a high number of requests within a short period. Such activity may indicate brute-force attacks or abnormal user behavior. By monitoring these events in real time, Splunk helps improve visibility into potential security threats and supports faster incident response.</p>
</sec>
<sec id="S3.SS8.SSS3">
<title>Recommended fix</title>
<p>Organizations should implement centralized log management and configure alerts for unusual activities such as repeated login attempts and excessive requests from a single IP address. Regular log analysis can help detect threats early and strengthen overall security monitoring.</p>
<fig id="F20" position="float">
<label>FIGURE 20</label>
<caption><p>Log analysis and monitoring in the Splunk dashboard.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g020.tif"/>
</fig>
</sec>
</sec>
<sec id="S3.SS9">
<title>Using components with known vulnerabilities</title>
<p>Refer to <xref ref-type="fig" rid="F21">Figure 21</xref> for additional information.</p>
<fig id="F21" position="float">
<label>FIGURE 21</label>
<caption><p>Exposure of outdated hypertext preprocessor (PHP) version (5.3.2).</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g0021.tif"/>
</fig>
<sec id="S3.SS9.SSS1">
<title>Recommended fix</title>
<p>Maintain an up-to-date inventory of all software components, libraries, frameworks, and dependencies used in the application. Regularly monitor for security updates and patches, remove unsupported or unnecessary components, and promptly update vulnerable dependencies. Use automated vulnerability scanning tools to identify and remediate known security flaws before deployment.</p>
</sec>
</sec>
<sec id="S3.SS10">
<title>Unvalidated redirects and forwards</title>
<p>Refer to <xref ref-type="fig" rid="F22">Figures 22</xref> and <xref ref-type="fig" rid="F23">23</xref> for additional information.</p>
<fig id="F22" position="float">
<label>FIGURE 22</label>
<caption><p>Unvalidated redirect demonstration.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g0022.tif"/>
</fig>
<fig id="F23" position="float">
<label>FIGURE 23</label>
<caption><p>Successful URL manipulation demonstrating A10 &#x2013; unvalidated redirect vulnerability.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="bijscit-2026-53-g0023.tif"/>
</fig>
<sec id="S3.SS10.SSS1">
<title>Recommended fix</title>
<p>Avoid using user-supplied input directly in redirect or forward destinations. Implement a whitelist of approved uniform resource locators (URLs) and validate all redirect targets before processing. Use indirect references or server-side mappings for redirects and display a warning page when redirecting users to external websites.</p>
</sec>
</sec>
</sec>
<sec id="S4" sec-type="discussion">
<title>Discussion</title>
<p>The security testing performed on DVWA, bWAPP, and Mutillidae showed that web applications can contain several security weaknesses if proper security measures are not followed. The vulnerabilities identified during the assessment matched many categories of the OWASP Top 10, proving that these risks are still common in web applications.</p>
<p>The results showed that vulnerabilities such as Broken Access Control, SQL Injection, Security Misconfiguration, CSRF, and Authentication Failures can seriously affect the confidentiality, integrity, and availability of web applications. If these vulnerabilities are exploited by attackers, sensitive information may be exposed or modified without authorization.</p>
<p>The study also demonstrated that many security issues can be prevented by following secure coding practices, implementing proper authentication and authorization controls, validating user inputs, and regularly updating system configurations. Security testing tools helped identify vulnerabilities efficiently and provided valuable insights into application weaknesses.</p>
<p>Overall, the findings emphasize the importance of regularly assessing web applications for security vulnerabilities. Using the OWASP Top 10 as a security guideline helps developers and organizations build more secure applications and reduce the risk of cyberattacks.</p>
</sec>
<sec id="S5" sec-type="results">
<title>Results</title>
<p>The security assessment was conducted on three vulnerable web applications: DVWA, bWAPP, and Mutillidae. Various OWASP Top 10 vulnerabilities were tested and successfully identified using security testing techniques and tools.</p>
<p>The results showed that all three applications contained multiple security weaknesses, including Broken Access Control, Injection, Security Misconfiguration, Identification and Authentication Failures, Insecure Design, CSRF, and Security Logging and Monitoring Failures.</p>
<p>SQL Injection vulnerabilities allowed unauthorized access to database information by manipulating user input fields. Broken Access Control vulnerabilities enabled access to restricted resources without proper authorization. Authentication weaknesses demonstrated the risks associated with weak login mechanisms and poor session management.</p>
<p>Security misconfiguration issues were identified through default settings and improper application configurations. CSRF attacks were successfully performed, showing that unauthorized actions could be executed on behalf of authenticated users. In addition, insufficient logging and monitoring mechanisms made it difficult to detect malicious activities.</p>
<p>The findings indicate that web applications are highly vulnerable when security controls are not properly implemented. The OWASP Top 10 framework provided an effective approach for identifying and understanding these security risks. The results highlight the importance of secure coding practices, regular vulnerability assessments, and proper security configurations to protect web applications from cyber threats.</p>
</sec>
<sec id="S6" sec-type="conclusion">
<title>Conclusion</title>
<p>This study evaluated the security of web applications using the OWASP Top 10 framework. Security testing was conducted on DVWA, bWAPP, and Mutillidae to identify common web application vulnerabilities. The results showed the presence of several security weaknesses, including Broken Access Control, Injection, Security Misconfiguration, Identification and Authentication Failures, CSRF, and Security Logging and Monitoring Failures.</p>
<p>The findings demonstrate that web applications can be vulnerable to various cyberattacks if proper security controls are not implemented. The study highlights the importance of secure coding practices, regular vulnerability assessments, proper authentication mechanisms, and secure system configurations to improve application security.</p>
<p>One limitation of this study is that the testing was performed on intentionally vulnerable applications in a controlled laboratory environment. Therefore, the results may not fully represent the security challenges found in real-world production systems.</p>
<p>Future research can focus on assessing modern web applications, integrating automated security testing tools, and evaluating advanced security mechanisms for detecting and preventing emerging cyber threats. Continuous security assessment and adherence to OWASP guidelines will help organizations build more secure and resilient web applications.</p>
</sec>
<sec id="S7" sec-type="author-contributions">
<title>Author contributions</title>
<p>S.B. conceived and supervised the study. S.H. conducted the experiments, collected data, performed security assessments, and prepared the manuscript. Both authors reviewed and approved the final manuscript.</p>
</sec>
</body>
<back>
<sec id="S8" sec-type="funding-information">
<title>Funding</title>
<p>The authors declare that financial support was not received for this work and/or its publication.</p>
</sec>
<ack><p>The authors would like to thank PSGR Krishnammal College for Women for providing the resources and support required to complete this research work.</p>
</ack>
<sec id="S9">
<title>Conflict of interest</title>
<p>The authors declare that the research was conducted in the absence of any commercial or financial relationships that could be construed as a potential conflict of interest.</p>
</sec>
<ref-list>
<title>References</title>
<ref id="B1"><label>1.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Syarifudin</surname> <given-names>M</given-names></name> <name><surname>Widyawati</surname> <given-names>L</given-names></name> <name><surname>Asroni</surname> <given-names>O</given-names></name></person-group>. <article-title>Web security vulnerability analysis and mitigation based on OWASP TOP 10</article-title>. <source><italic>J Artif Intell Eng Appl (JAIEA)</italic></source>. (<year>2025</year>) <volume>4</volume>(<issue>3</issue>):<fpage>1829</fpage>&#x2013;<lpage>34</lpage>.</citation></ref>
<ref id="B2"><label>2.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Li</surname> <given-names>Y</given-names></name> <name><surname>Li</surname> <given-names>X</given-names></name></person-group>. <article-title>Evolution of application security based on OWASP top 10 and CWE/SANS top 25 with predictions for the 2025 OWASP top 10</article-title>. <source><italic>ICICT 2025 Conference</italic></source>. (<year>2025</year>).</citation></ref>
<ref id="B3"><label>3.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Patil</surname> <given-names>S</given-names></name> <name><surname>Rao</surname> <given-names>M</given-names></name> <name><surname>Misal</surname> <given-names>L</given-names></name> <name><surname>Phaldesai</surname> <given-names>D</given-names></name> <name><surname>Shivsharan</surname> <given-names>K</given-names></name></person-group>. <article-title>A review of the OWASP top 10 web application security risks and best practices</article-title>. <source><italic>ICCUBEA 2023 Conference</italic></source>. (<year>2023</year>).</citation></ref>
<ref id="B4"><label>4.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Rohmaniah</surname> <given-names>D</given-names></name> <name><surname>Ashari</surname> <given-names>WM</given-names></name> <name><surname>Lukman</surname> <given-names>L</given-names></name> <name><surname>Putra</surname> <given-names>AD</given-names></name></person-group>. <article-title>Enhancing Website Security Using VAPT Based on OWASP Top Ten</article-title>. <source><italic>J Appl Inform Comput</italic></source>. (<year>2025</year>) <volume>9</volume>(<issue>2</issue>):<fpage>404</fpage>&#x2013;<lpage>11</lpage>.</citation></ref>
<ref id="B5"><label>5.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Qadir</surname> <given-names>S</given-names></name> <name><surname>Waheed</surname> <given-names>E</given-names></name> <name><surname>Khanum</surname> <given-names>A</given-names></name> <name><surname>Jehan</surname> <given-names>S</given-names></name></person-group>. <article-title>Comparative evaluation of approaches tools for security testing of web applications</article-title>. <source><italic>PeerJ Comput Sci</italic></source>. (<year>2025</year>) <volume>11</volume>:<fpage>e2821</fpage>.</citation></ref>
<ref id="B6"><label>6.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Fredj</surname> <given-names>OB</given-names></name> <name><surname>Cheikhrouhou</surname> <given-names>O</given-names></name> <name><surname>Krichen</surname> <given-names>M</given-names></name> <name><surname>Hamam</surname> <given-names>H</given-names></name></person-group>. <article-title>An OWASP top ten driven survey on web application protection methods.</article-title> <source><italic>Proc. Int. Conf. Risks and Security of Internet and Systems.</italic></source> <publisher-loc>Cham</publisher-loc>: <publisher-name>Springer International Publishing</publisher-name> (<year>2020</year>).</citation></ref>
<ref id="B7"><label>7.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Kumar</surname> <given-names>A</given-names></name> <name><surname>Rani</surname> <given-names>S</given-names></name></person-group>. <article-title>Implementation and analysis of web application security measures using OWASP guidelines</article-title>. <source><italic>ICMACC 2022 Conference</italic></source>. (<year>2022</year>).</citation></ref>
<ref id="B8"><label>8.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Nawrocki</surname> <given-names>M</given-names></name> <name><surname>Ko&#x0142;odziej</surname> <given-names>J</given-names></name></person-group>. <article-title>Vulnerabilities of web applications: Good practices and new trends</article-title>. <source><italic>Appl Cybersec Int Gov</italic></source>. (<year>2024</year>) <volume>3</volume>(<issue>2</issue>):<fpage>122</fpage>&#x2013;<lpage>43</lpage>.</citation></ref>
<ref id="B9"><label>9.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Nedeljkovi&#x0107;</surname> <given-names>N</given-names></name> <name><surname>Vugdelija</surname> <given-names>N</given-names></name> <name><surname>Koji&#x0107;</surname> <given-names>N</given-names></name></person-group>. <article-title>Use of OWASP Top 10 in web application security.</article-title> <source><italic>Proc. Fourth Int. Scientific Conf. Recent Advances in Information Technology, Tourism, Economics, Management and Agriculture.</italic></source> (<year>2020</year>).</citation></ref>
<ref id="B10"><label>10.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Lala</surname> <given-names>SK</given-names></name> <name><surname>Kumar</surname> <given-names>A</given-names></name></person-group>. <article-title>Secure web development using OWASP guidelines.</article-title> <source><italic>Proc. 5th Int. Conf. Intelligent Computing and Control Systems (ICICCS).</italic></source> <publisher-loc>Madurai, India</publisher-loc>: <publisher-name>IEEE</publisher-name> (<year>2021</year>).</citation></ref>
<ref id="B11"><label>11.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Idris</surname> <given-names>M</given-names></name> <name><surname>Syarif</surname> <given-names>I</given-names></name> <name><surname>Winarno</surname> <given-names>I</given-names></name></person-group>. <article-title>Web application security education platform based on OWASP API security project.</article-title> <source><italic>EMITTER Int J Eng Technol.</italic></source> (<year>2022</year>) <volume>10</volume>(<issue>2</issue>):<fpage>246</fpage>&#x2013;<lpage>61</lpage>.</citation></ref>
<ref id="B12"><label>12.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Willberg</surname> <given-names>M.</given-names></name></person-group> <source><italic>Web Application Security Testing with OWASP Top 10 Framework.</italic></source> <publisher-loc>Turku (Finland)</publisher-loc>: <publisher-name>Turku University of Applied Sciences</publisher-name> (<year>2019</year>).</citation></ref>
<ref id="B13"><label>13.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Helmiawan</surname> <given-names>MA</given-names></name> <name><surname>Firmansyah</surname> <given-names>E</given-names></name> <name><surname>Fadil</surname> <given-names>I</given-names></name> <name><surname>Sofivan</surname> <given-names>Y</given-names></name> <name><surname>Mahardika</surname> <given-names>F</given-names></name> <name><surname>Guntara</surname> <given-names>A</given-names></name></person-group>. <article-title>Analysis of web security using open web application security project 10.</article-title> <source><italic>Proc. 8th Int. Conf. Cyber and IT Service Management (CITSM).</italic></source> <publisher-loc>Pangkal, Indonesia. Piscataway (NJ)</publisher-loc>: <publisher-name>IEEE</publisher-name> (<year>2020</year>). <fpage>2020</fpage> p.</citation></ref>
<ref id="B14"><label>14.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Ventura</surname> <given-names>R</given-names></name> <name><surname>Franco</surname> <given-names>DJ</given-names></name> <name><surname>Akram</surname> <given-names>OK.</given-names></name></person-group> <source><italic>A Novel VAPT Algorithm: Enhancing Web Application Security Through OWASP Top 10 Optimization.</italic></source> <publisher-name>arXiv Preprint arXiv:2311.10450</publisher-name> (<year>2023</year>).</citation></ref>
<ref id="B15"><label>15.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>King</surname> <given-names>J.</given-names></name></person-group> <source><italic>Android Application Security with OWASP Mobile Top 10.</italic></source> <publisher-name>OWASP</publisher-name> (<year>2014</year>).</citation></ref>
<ref id="B16"><label>16.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Wen</surname> <given-names>SF</given-names></name> <name><surname>Katt</surname> <given-names>B</given-names></name></person-group>. <article-title>A quantitative security evaluation and analysis model for web applications based on OWASP Application Security Verification Standard.</article-title> <source><italic>Comput Secur.</italic></source> (<year>2023</year>) <volume>135</volume>:<fpage>103532</fpage>.</citation></ref>
<ref id="B17"><label>17.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Simplice</surname> <given-names>I</given-names></name> <name><surname>Fidel</surname> <given-names>O</given-names></name> <name><surname>Kennedy</surname> <given-names>GC</given-names></name> <name><surname>Okokpujie</surname> <given-names>K</given-names></name></person-group>. <article-title>Enhancing information system security: a vulnerability assessment of a web application using OWASP Top 10 list.</article-title> <source><italic>Proc. Int. Conf. Smart Computing and Cyber Security.</italic></source> <publisher-loc>Singapore</publisher-loc>: <publisher-name>Springer Nature Singapore</publisher-name> (<year>2023</year>).</citation></ref>
<ref id="B18"><label>18.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Nilsson</surname> <given-names>D</given-names></name> <name><surname>&#x00C5;berg</surname> <given-names>H.</given-names></name></person-group> <source><italic>HTML5 Web Application Security with OWASP.</italic></source> <publisher-loc>Karlskrona (Sweden)</publisher-loc>: <publisher-name>Blekinge Institute of Technology, School of Computing</publisher-name> (<year>2013</year>).</citation></ref>
<ref id="B19"><label>19.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Tudela</surname> <given-names>FM</given-names></name> <name><surname>Higuera</surname> <given-names>JRB</given-names></name> <name><surname>Higuera</surname> <given-names>JB</given-names></name> <name><surname>Montalvo</surname> <given-names>JAS</given-names></name> <name><surname>Argyros</surname> <given-names>MI</given-names></name></person-group>. <article-title>On combining static, dynamic and interactive analysis security testing tools to improve OWASP Top Ten security vulnerability detection in web applications.</article-title> <source><italic>Appl Sci.</italic></source> (<year>2020</year>) <volume>10</volume>(<issue>24</issue>):<fpage>9119</fpage>.</citation></ref>
<ref id="B20"><label>20.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Rafique</surname> <given-names>S</given-names></name> <name><surname>Humayun</surname> <given-names>M</given-names></name> <name><surname>Hamid</surname> <given-names>B</given-names></name> <name><surname>Abbas</surname> <given-names>A</given-names></name> <name><surname>Akhtar</surname> <given-names>I</given-names></name> <name><surname>Iqbal</surname> <given-names>K</given-names></name></person-group>. <article-title>Web application security vulnerabilities detection approaches: a systematic mapping study.</article-title> In: <person-group person-group-type="editor"><name><surname>Lee</surname> <given-names>R</given-names></name></person-group><role>editor.</role> <source><italic>Proc. IEEE/ACIS 16th Int. Conf. Software Engineering, Artificial Intelligence, Networking and Parallel/Distributed Computing (SNPD).</italic></source> <publisher-loc>Piscataway (NJ)</publisher-loc>: <publisher-name>IEEE</publisher-name> (<year>2015</year>).</citation></ref>
<ref id="B21"><label>21.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Silva</surname> <given-names>JCB.</given-names></name></person-group> <source><italic>Evaluation of Dynamic Analysis Tools in Detecting OWASP Top 10 Vulnerabilities.</italic></source> <publisher-name>MS Thesis, Universidade de Coimbra</publisher-name> (<year>2024</year>).</citation></ref>
<ref id="B22"><label>22.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Jakobsson</surname> <given-names>A</given-names></name> <name><surname>H&#x00E4;ggstr&#x00F6;m</surname> <given-names>I.</given-names></name></person-group> <source><italic>Study of the Techniques Used by OWASP ZAP for Analysis of Vulnerabilities in Web Applications.</italic></source> <publisher-loc>Link&#x00F6;ping (Sweden)</publisher-loc>: <publisher-name>Link&#x00F6;ping University, Department of Computer and Information Science</publisher-name> (<year>2022</year>).</citation></ref>
<ref id="B23"><label>23.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Ksiezopolski</surname> <given-names>B</given-names></name> <name><surname>Mazur</surname> <given-names>K</given-names></name> <name><surname>Miskiewicz</surname> <given-names>M</given-names></name> <name><surname>Rusinek</surname> <given-names>D</given-names></name></person-group>. <article-title>Teaching a hands-on CTF-based web application security course.</article-title> <source><italic>Electronics</italic></source> (<year>2022</year>) <volume>11</volume>(<issue>21</issue>):<fpage>3517</fpage>.</citation></ref>
<ref id="B24"><label>24.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Riadi</surname> <given-names>I</given-names></name> <name><surname>Raharja</surname> <given-names>PA</given-names></name></person-group>. <article-title>Vulnerability analysis of E-voting application using Open Web Application Security Project (OWASP) framework.</article-title> <source><italic>Int J Adv Comput Sci Appl.</italic></source> (<year>2019</year>) <volume>10</volume>(<issue>11</issue>):<fpage>135</fpage>&#x2013;<lpage>43</lpage>.</citation></ref>
<ref id="B25"><label>25.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Idris</surname> <given-names>M</given-names></name> <name><surname>Syarif</surname> <given-names>I</given-names></name> <name><surname>Winarno</surname> <given-names>I</given-names></name></person-group>. <article-title>Development of vulnerable web application based on OWASP API security risks.</article-title> <source><italic>Proc. International Electronics Symposium (IES).</italic></source> <publisher-loc>Piscataway (NJ)</publisher-loc>: <publisher-name>IEEE</publisher-name> (<year>2021</year>).</citation></ref>
<ref id="B26"><label>26.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Cordella</surname> <given-names>A.</given-names></name></person-group> <source><italic>Web Application Penetration Testing: An Analysis of a Corporate Application According to OWASP Guidelines.</italic></source> <publisher-loc>Bologna</publisher-loc>: <publisher-name>Alma Mater Studioum University Of Bologna</publisher-name> (<year>2018</year>).</citation></ref>
<ref id="B27"><label>27.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Goswami</surname> <given-names>S</given-names></name> <name><surname>Krishnan</surname> <given-names>NR</given-names></name> <name><surname>Mukesh, Swarnkar</surname> <given-names>S</given-names></name> <name><surname>Mahajan</surname> <given-names>P</given-names></name></person-group>. <article-title>Reducing attack surface of a web application by Open Web Application Security Project compliance.</article-title> <source><italic>Def Sci J.</italic></source> (<year>2012</year>) <volume>62</volume>(<issue>5</issue>):<fpage>324</fpage>&#x2013;<lpage>30</lpage>.</citation></ref>
</ref-list>
</back>
</article>
