📖 ABSTRACT/OVERVIEW
Learning management systems deployed in Nigerian universities contain student data and assessment records that benefit from regular security testing, and empirically evaluating penetration testing effectiveness provides evidence for institutional security governance policy. This study empirically evaluated the effectiveness of penetration testing in identifying security vulnerabilities in LMS instances at four federal universities: University of Lagos, Obafemi Awolowo University, Ahmadu Bello University, and University of Nigeria Nsukka. A structured penetration testing methodology aligned with OWASP Testing Guide was applied to each LMS instance with formal institutional authorisation. Testing phases covered authentication, input validation, session management, access control, and API security. Results showed 73 vulnerabilities across four LMS instances, averaging 18.3 per institution. Critical-severity vulnerabilities were found in all four, including SQL injection (3 instances), broken access control allowing unauthorised grade access (4 instances), and authentication bypass (2 instances). Mean time to patch critical vulnerabilities after reporting was 22.4 days. Two universities had not patched reported critical vulnerabilities within 60 days of notification. None of the four universities had conducted prior LMS security testing. The study provides empirical evidence of significant LMS security risk and recommends mandatory annual LMS penetration testing as a NUC accreditation requirement, alongside rapid patch response standards and LMS security configuration baseline requirements for all Nigerian federal universities.
Keywords: penetration testing, learning management system, university cybersecurity, vulnerability assessment, Nigeria
Need Complete Chapters of the Above Topic?
Get high-quality, Zero-AI research materials with current citations.
Request via WhatsApp 💬