Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Using a web vulnerability scanner to find and patch security vulnerabilities in a selection of web applications
Blekinge Institute of Technology, Faculty of Computing, Department of Software Engineering.
2025 (English)Independent thesis Basic level (university diploma), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

Web applications are of critical importance in today's digital landscape. This means their security is of equal importance both for the users and owners of these applications. However, the increasing complexity and variety of technologies used for building web applications coupled with the diverse threats posed by cyber attacks makes identifying and addressing vulnerabilities a challenging prospect. This study looks into using OWASP ZAP, a web vulnerability scanner, for this very purpose for three different applications hosted locally.

This is done using a systematic approach where vulnerabilities are identified through scans and analyzed for impact and risks, after which they are addressed through targeted patches. During the patching process, applications are re-scanned to ensure the effectiveness of the implemented solutions (and disappearance of alerts). This process highlights recurring vulnerabilities that are common across the three investigated applications. This includes universal, well-known web application vulnerabilities like Cross-site scripting (XSS), SQL injection and insecure configurations.

The findings demonstrate the usefulness of using web vulnerability scanners for streamlining the detection and patching process of security risks in modern  applications. It also emphasizes the importance of not overlooking secure coding practices, implementing robust configurations and not treating security as an afterthought. It presents actionable recommendations which provides developers with practical insights into using automated scanning tools as a routine part of their workflow, contributing to stronger web application security.

Place, publisher, year, edition, pages
2025. , p. 50
Keywords [en]
OWASP, web vulnerability scanner, ZAP, web application security
National Category
Software Engineering
Identifiers
URN: urn:nbn:se:bth-27391OAI: oai:DiVA.org:bth-27391DiVA, id: diva2:1935259
Subject / course
PA1438 Självständigt arbete Webbprogrammering
Educational program
PAGWG Webbprogrammering
Supervisors
Examiners
Available from: 2025-02-07 Created: 2025-02-06 Last updated: 2025-09-30Bibliographically approved

Open Access in DiVA

No full text in DiVA

By organisation
Department of Software Engineering
Software Engineering

Search outside of DiVA

GoogleGoogle Scholar

urn-nbn

Altmetric score

urn-nbn
Total: 116 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf