Skip to content
rootdarth

Sample report

What you receive at the end of a test

A redacted example of a RootDarth report. Client names, hosts and data have been replaced with sample values. The structure and level of detail are the same as a real engagement.

Penetration test report

Confidential

Web Application and API Penetration Test

Prepared for [Redacted] by RootDarth · Version 1.0

Client
[Redacted], fintech SaaS
Engagement
Web application and API test
Testing window
10 business days
Report date
May 2026
Methodology
OWASP WSTG v4.2, OWASP API Security Top 10
Classification
Confidential

1

Executive summary

RootDarth tested [Client]'s web application, public API and supporting AWS storage over 10 business days, following the OWASP Web Security Testing Guide (v4.2). AI-assisted tooling was used for reconnaissance and endpoint discovery. Every finding in this report was reproduced manually by the tester.

We identified five issues: one critical, two high and two medium. The most serious is an SQL injection in the user profile API (CVSS 9.8) that lets an unauthenticated attacker read the full user table, including password hashes.

Each finding includes reproduction steps and remediation guidance. The engineering team was briefed at the end of testing, and a retest is scheduled once fixes are deployed.

  • 1

    Critical
  • 2

    High
  • 2

    Medium
  • 0

    Low

2

Scope and approach

In scope

  • app.example.com (web application)
  • api.example.com (REST API, v2)
  • assets.prod.example.com (S3 bucket)

Out of scope

Denial of service, social engineering and third-party payment providers.

Approach

AI-assisted mapping of subdomains, JavaScript bundles and the API schema, followed by manual testing of authentication, authorization, input handling and business logic.

Verification

Candidate issues from automated and AI-assisted analysis were only reported after the tester reproduced them by hand.

3

Findings summary

  • F-001Critical9.8

    SQL injection in user profile API

    GET /api/v2/users/profile

  • F-002High8.1

    Broken object level authorization in payments API

    /api/v2/payments/{payment_id}

  • F-003High7.5

    Public read access on S3 bucket

    assets.prod.example.com

  • F-004Medium6.1

    Stored cross-site scripting in support tickets

    POST /support/tickets/create

  • F-005Medium5.3

    No rate limiting on login endpoint

    POST /api/v2/auth/login

4

F-001: SQL injection in user profile API

CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (9.8)
Affected
GET /api/v2/users/profile (id)
Weakness
CWE-89: SQL injection
How it was found
Flagged by AI-assisted schema review, confirmed manually

Description

The id parameter of /api/v2/users/profile is concatenated into a SQL query without parameterization. The endpoint does not require authentication, so anyone on the internet can change the logic of the query and read data from the database.

Reproduction

GET /api/v2/users/profile?id=1'+OR+1=1--+ HTTP/1.1
Host: api.example.com
Accept: application/json

HTTP/1.1 200 OK
Content-Type: application/json

[
  {"id": 1, "email": "admin@example.com", "role": "admin", "password_hash": "$2b$12$[redacted]"},
  {"id": 2, "email": "[redacted]", "role": "user", "password_hash": "$2b$12$[redacted]"},
  ...
]

The modified query returns every row in the users table (48,211 records at the time of testing) instead of a single profile.

Impact

An attacker can extract every user record, including email addresses and password hashes, and depending on database permissions can read other tables such as transactions. All customers whose data is stored in this database are affected.

Remediation

  1. Use parameterized queries (prepared statements) for all database access in this service.
  2. Validate id as a positive integer and reject anything else.
  3. Connect with a least-privilege database user that cannot read unrelated tables.
  4. Require authentication on the endpoint and return only the caller's own profile.

References

CWE-89 · OWASP WSTG-INPV-05 (Testing for SQL Injection)

5

What every report includes

  • Executive summary for leadership
  • CVSS-scored findings
  • Reproduction steps and evidence
  • Remediation guidance
  • Compliance mapping (SOC 2, PCI DSS, HIPAA, ISO 27001)
  • Free retest and an updated report

Request a proposal

Email a short description of what you want tested. It helps to include the targets (URLs, apps, IP ranges or repositories), any testing window, and the compliance standard you are working toward.

Response
A scoped proposal with a fixed price and timeline within one business day.
Confidentiality
Testing runs under a signed NDA, written authorization and agreed rules of engagement.
Included
Executive and technical report, plus a free retest of the findings you fix.