op/jbellsign out
phase
testing
rate
10/s
window ends
2026-10-09
status
running

The report lists every finding that isn't marked junk, ordered by severity. Export it as Markdown to edit or convert.

Acme Corp: web application penetration test

acme-web · 2026-09-28 to 2026-10-09

Scope

  • app.acme.testin scope
  • api.acme.testin scope
  • static.acme.testin scope
  • sso.acme.testexcluded
  • app.acme.test/admin/billing/*excluded

Summary

  • critical1
  • high1
  • medium2
  • low1
  • info1

Findings

  1. F-001criticalCWE-639open

    Order lookup returns other customers' orders

    GET /api/orders/:id

    The order endpoint checks that a session exists but not that the order belongs to it. Any customer can read any order by id.

    Remediation. Scope the order query to the session's customer id, and return 404 for orders the session does not own.

  2. F-002highCWE-918triaged

    Avatar import fetches internal addresses

    POST /api/users/:id/avatar

    The avatar import fetches the supplied URL from the server without restricting the destination.

    Remediation. Resolve the host first and reject private, loopback, and link-local ranges. Better: accept uploads instead of URLs.

  3. F-003mediumCWE-614open

    Session cookie lacks Secure and SameSite

    POST /login

    The session cookie is set without the Secure or SameSite attributes.

    Remediation. Set Secure, HttpOnly, and SameSite=Lax on the session cookie.

  4. F-004mediumCWE-79open

    Search query reflected unencoded in error page

    GET /search

    When search fails, the 500 page echoes the q parameter into the HTML without encoding it.

    Remediation. Encode q on output in the error template, and add a Content-Security-Policy.

  5. F-005lowCWE-209fixed

    Stack traces on malformed JSON

    POST /api/orders

    Malformed request bodies return a full Express stack trace with file paths.

    Remediation. Return a generic error body in production.

  6. F-006infoCWE-200open

    Server versions in response headers

    *

    Server and X-Powered-By headers name nginx 1.25.3 and Express.

    Remediation. Remove X-Powered-By and set server_tokens off.