Penetration test report
Confidential
Web Application and API Penetration Test
Prepared for [Redacted] by RootDarth · Version 1.0
- Client
- [Redacted], fintech SaaS
- Engagement
- Web application and API test
- Testing window
- 10 business days
- Report date
- May 2026
- Methodology
- OWASP WSTG v4.2, OWASP API Security Top 10
- Classification
- Confidential
1
Executive summary
RootDarth tested [Client]'s web application, public API and supporting AWS storage over 10 business days, following the OWASP Web Security Testing Guide (v4.2). AI-assisted tooling was used for reconnaissance and endpoint discovery. Every finding in this report was reproduced manually by the tester.
We identified five issues: one critical, two high and two medium. The most serious is an SQL injection in the user profile API (CVSS 9.8) that lets an unauthenticated attacker read the full user table, including password hashes.
Each finding includes reproduction steps and remediation guidance. The engineering team was briefed at the end of testing, and a retest is scheduled once fixes are deployed.
1
Critical2
High2
Medium0
Low
2
Scope and approach
In scope
app.example.com(web application)api.example.com(REST API, v2)assets.prod.example.com(S3 bucket)
Out of scope
Approach
Verification
3
Findings summary
- F-001Critical9.8
SQL injection in user profile API
GET /api/v2/users/profile
- F-002High8.1
Broken object level authorization in payments API
/api/v2/payments/{payment_id}
- F-003High7.5
Public read access on S3 bucket
assets.prod.example.com
- F-004Medium6.1
Stored cross-site scripting in support tickets
POST /support/tickets/create
- F-005Medium5.3
No rate limiting on login endpoint
POST /api/v2/auth/login
| ID | Finding | Severity | CVSS 3.1 |
|---|---|---|---|
| F-001 | SQL injection in user profile API GET /api/v2/users/profile | Critical | 9.8 |
| F-002 | Broken object level authorization in payments API /api/v2/payments/{payment_id} | High | 8.1 |
| F-003 | Public read access on S3 bucket assets.prod.example.com | High | 7.5 |
| F-004 | Stored cross-site scripting in support tickets POST /support/tickets/create | Medium | 6.1 |
| F-005 | No rate limiting on login endpoint POST /api/v2/auth/login | Medium | 5.3 |
4
F-001: SQL injection in user profile API
- Affected
- GET /api/v2/users/profile (id)
- Weakness
- CWE-89: SQL injection
- How it was found
- Flagged by AI-assisted schema review, confirmed manually
Description
id parameter of /api/v2/users/profile is concatenated into a SQL query without parameterization. The endpoint does not require authentication, so anyone on the internet can change the logic of the query and read data from the database.Reproduction
GET /api/v2/users/profile?id=1'+OR+1=1--+ HTTP/1.1
Host: api.example.com
Accept: application/json
HTTP/1.1 200 OK
Content-Type: application/json
[
{"id": 1, "email": "admin@example.com", "role": "admin", "password_hash": "$2b$12$[redacted]"},
{"id": 2, "email": "[redacted]", "role": "user", "password_hash": "$2b$12$[redacted]"},
...
]The modified query returns every row in the users table (48,211 records at the time of testing) instead of a single profile.
Impact
Remediation
- Use parameterized queries (prepared statements) for all database access in this service.
- Validate
idas a positive integer and reject anything else. - Connect with a least-privilege database user that cannot read unrelated tables.
- Require authentication on the endpoint and return only the caller's own profile.
References
5
What every report includes
- Executive summary for leadership
- CVSS-scored findings
- Reproduction steps and evidence
- Remediation guidance
- Compliance mapping (SOC 2, PCI DSS, HIPAA, ISO 27001)
- Free retest and an updated report