Abstract:
This independent study is for studying the website vulnerability assessment in an organization and analyzing the vulnerability, which is based on the OWASP Top 10 2021. In this study, three free license tools are considered, which are OWASP ZAP, Acunetix, and WPScan and tested on three developed websites of the organization. The result showed that the Acunetix was able to assess available vulnerabilities more efficiently than OWASP ZAP, and WPScan. From the OWASP Top 10 2021, it found that the top three categories with the highest number of vulnerabilities were A05 : Security Misconfiguration, A01 : Broken Access Control, and A02 : Cryptographic Failures, with 30.43%, 26.09%, 21.74% of found, respectively. Finally, the guidelines of website developing handbook was published based on the OWASP Top 10 2021, in order to develop the website safely. The handbook was evaluated by seven information technology experts, the result showed that the satisfaction level of the book is around 89.14% with high acceptable.