Skip to main content
SAMPLE SECURITY DELIVERABLE

Sample Penetration Testing Report

This interactive document demonstrates the structure, technical depth, CVSS severity modeling, evidence quality, and remediation playbooks included in all RajSecure security assessment deliverables.

Confidentiality Notice: All hostnames, client identifiers, and IP addresses in this document are fictionalized and labeled as a SAMPLE for demonstration purposes.
Security Assessment Deliverable

Web Application & API Penetration Test

Prepared by RajSecure • Ref: RAJ-SEC-SAMPLE-2026

FINAL REPORT • VERIFIED RETEST

Classification: Strictly Confidential

1. Executive Summary

Between March 10, 2026, and March 20, 2026, RajSecure conducted an authorized offensive security assessment against the target web application and associated API infrastructure for Acme Global Systems Ltd. (Sample Client). The objective of this engagement was to identify exploitable security vulnerabilities, assess data access control boundaries, evaluate business logic, and provide actionable remediation guidance.

1Critical
2High
3Medium
2Low / Info

Status Update: Following remediation verification retesting on April 5, 2026, all Critical and High vulnerabilities have been validated as successfully resolved.

2. Scope & Rules of Engagement

Target Domain: https://app.sample-client.com
API Gateway: https://api.sample-client.com/v2/
Testing Perspective: Authenticated Grey-Box (2 User Roles)
Engagement Dates: March 10 - March 20, 2026
  • ✓ Written Authorization Verified: Signed RoE Ref #ROE-2026-049
  • ✓ Data Protection: All captured test tokens securely purged following verification
  • ✓ Production Impact: Zero downtime recorded during testing window

3. Severity Scoring Methodology

Vulnerabilities are evaluated using the Common Vulnerability Scoring System (CVSS v3.1) combined with contextual business impact assessment:

Critical (9.0 - 10.0)
Direct system or data takeover
High (7.0 - 8.9)
Significant access or privilege escalation
Medium (4.0 - 6.9)
Partial data leakage or bypass
Low (0.1 - 3.9)
Information disclosure / hardening

4. Sample Vulnerability Finding Detail

CRITICALVULN-01 • CWE-639 / OWASP API1:2023

Broken Object-Level Authorization (BOLA) in Customer Invoice Export API

CVSS 3.1: 9.1

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Description: The endpoint GET /api/v2/organizations/{org_id}/invoices/{invoice_id}.pdf fails to validate that the requesting authenticated user has authorization to access the specified organization_id. An authenticated user belonging to Organization A can download confidential invoices and billing data from Organization B by changing the URL parameter.

Proof of Concept (PoC) Request:
GET /api/v2/organizations/org_98231/invoices/inv_2026_0941.pdf HTTP/1.1
Host: api.sample-client.com
Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9... (Token of Org B User)
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64)
Observed Server Response (Data Exfiltration Validated):
HTTP/1.1 200 OK
Content-Type: application/pdf
Content-Disposition: attachment; filename="Acme_Corp_Invoice_March2026.pdf"
Content-Length: 48921

%PDF-1.4 ... [Confidential Customer Billing Data Returned]
Business Impact Analysis:

An attacker with standard authenticated viewer credentials could automate an enumeration script across invoice IDs to harvest complete customer lists, payment histories, pricing contracts, and confidential financial records across all tenant accounts.

Remediation Guidance:

Implement strict server-side authorization checks comparing the authenticated session context against the requested resource ownership before querying the database:

// Secure Authorization Middleware Example
const orgId = req.params.orgId;
const userSessionOrg = req.user.organizationId;

if (orgId !== userSessionOrg && !req.user.isPlatformSuperAdmin) {
  return res.status(403).json({ error: 'Access Denied: Cross-tenant access prohibited' });
}
VERIFICATION RETEST RESULT — STATUS: RESOLVED

Retest conducted on April 5, 2026. Requesting unauthorized invoice IDs now yields HTTP 403 Forbidden with zero data exposure. The vulnerability is verified as closed.

Official Letter of Attestation Included

Upon verified retesting, RajSecure provides a formal Executive Letter of Attestation suitable for sharing with enterprise procurement teams, compliance auditors (SOC 2, ISO 27001, PCI DSS), and customer security reviews.