OWASP A03 Injection Vulnerability in Web Application Development

dc.citation.epage116
dc.citation.issue1
dc.citation.spage107
dc.citation.volume57
dc.contributor.authorLim Phei Chin
dc.contributor.authorAndy Chieng Ging Wei
dc.contributor.authorLing Huo Chong
dc.contributor.authorNurfauza Jali
dc.contributor.departmentFaculty of Computer Science and Information Technology
dc.date.accessioned2026-03-12T08:23:25Z
dc.date.issued2026
dc.description.abstractWeb applications are crucial for businesses and individuals by providing efficient communication, collaboration, and access to services and information via browsers, boosting connectedness, productivity, and creativity in the digital era. Insecure web applications pose risks of data breaches, malware, and unauthorized access which jeopardize user privacy, trust, and organizational security. Web developers must be knowledgeable and prepared to deal with common vulnerabilities in web applications. A prototype web application (https://webriska3.tech) with lesson and editor module is developed to train web developers on the Open Web Application Security Project (OWASP) Top Ten security risks, focusing on A03 - Injection vulnerability. OWASP A03 Injection vulnerability is one of the most common vulnerabilities that is at the heart of any database-driven web applications. Evaluation on the prototype in improvement knowledge on A03 – Injection vulnerability, testers are recruited to complete two coding tasks in laboratory environment. 80% of testers mastered Output escaping/encoding defensive technique while Prepared statement/Parameterized Query defensive technique is the hardest to master. The prototype obtained average System Usability Scale (SUS) score of 57 that is below average, indicating issues with the prototype interface. This work showed promising results of increase understanding on A03 Injection vulnerability and implementation skills to protect web application against attack and exploitations.
dc.description.referencesUncontrolled Keywords: OWASP Top 10; Web application vulnerability; Web security; SQL injection.
dc.description.statusPublished
dc.identifier.doihttps://doi.org/10.37934/araset.57.1.107116
dc.identifier.emailpclim@unimas.my
dc.identifier.emailjnurfauza@unimas.my
dc.identifier.issn2462-1943
dc.identifier.urihttps://semarakilmu.com.my/journals/index.php/applied_sciences_eng_tech/article/view/5359
dc.identifier.urihttps://scholarhub.unimas.my/handle/123456789/198
dc.publisherSemarak Ilmu Publishing
dc.relation.ispartofJournal of Advanced Research in Applied Sciences and Engineering Technology
dc.titleOWASP A03 Injection Vulnerability in Web Application Development
dc.typeArticles
dc.type.statusYes

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
OWASP A03 Injection.pdf
Size:
526.64 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed to upon submission
Description:

Collections