Sample Penetration Testing Report
This interactive document demonstrates the structure, technical depth, CVSS severity modeling, evidence quality, and remediation playbooks included in all RajSecure security assessment deliverables.
Web Application & API Penetration Test
Prepared by RajSecure • Ref: RAJ-SEC-SAMPLE-2026
Classification: Strictly Confidential
1. Executive Summary
Between March 10, 2026, and March 20, 2026, RajSecure conducted an authorized offensive security assessment against the target web application and associated API infrastructure for Acme Global Systems Ltd. (Sample Client). The objective of this engagement was to identify exploitable security vulnerabilities, assess data access control boundaries, evaluate business logic, and provide actionable remediation guidance.
Status Update: Following remediation verification retesting on April 5, 2026, all Critical and High vulnerabilities have been validated as successfully resolved.
2. Scope & Rules of Engagement
https://app.sample-client.comhttps://api.sample-client.com/v2/- ✓ Written Authorization Verified: Signed RoE Ref #ROE-2026-049
- ✓ Data Protection: All captured test tokens securely purged following verification
- ✓ Production Impact: Zero downtime recorded during testing window
3. Severity Scoring Methodology
Vulnerabilities are evaluated using the Common Vulnerability Scoring System (CVSS v3.1) combined with contextual business impact assessment:
Direct system or data takeover
Significant access or privilege escalation
Partial data leakage or bypass
Information disclosure / hardening
4. Sample Vulnerability Finding Detail
Broken Object-Level Authorization (BOLA) in Customer Invoice Export API
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Description: The endpoint GET /api/v2/organizations/{org_id}/invoices/{invoice_id}.pdf fails to validate that the requesting authenticated user has authorization to access the specified organization_id. An authenticated user belonging to Organization A can download confidential invoices and billing data from Organization B by changing the URL parameter.
GET /api/v2/organizations/org_98231/invoices/inv_2026_0941.pdf HTTP/1.1 Host: api.sample-client.com Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9... (Token of Org B User) User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64)
HTTP/1.1 200 OK Content-Type: application/pdf Content-Disposition: attachment; filename="Acme_Corp_Invoice_March2026.pdf" Content-Length: 48921 %PDF-1.4 ... [Confidential Customer Billing Data Returned]
An attacker with standard authenticated viewer credentials could automate an enumeration script across invoice IDs to harvest complete customer lists, payment histories, pricing contracts, and confidential financial records across all tenant accounts.
Implement strict server-side authorization checks comparing the authenticated session context against the requested resource ownership before querying the database:
// Secure Authorization Middleware Example
const orgId = req.params.orgId;
const userSessionOrg = req.user.organizationId;
if (orgId !== userSessionOrg && !req.user.isPlatformSuperAdmin) {
return res.status(403).json({ error: 'Access Denied: Cross-tenant access prohibited' });
}Retest conducted on April 5, 2026. Requesting unauthorized invoice IDs now yields HTTP 403 Forbidden with zero data exposure. The vulnerability is verified as closed.
Official Letter of Attestation Included
Upon verified retesting, RajSecure provides a formal Executive Letter of Attestation suitable for sharing with enterprise procurement teams, compliance auditors (SOC 2, ISO 27001, PCI DSS), and customer security reviews.