Acme Corp: web application penetration test
acme-web · 2026-09-28 to 2026-10-09
Scope
- app.acme.testin scope
- api.acme.testin scope
- static.acme.testin scope
- sso.acme.testexcluded
- app.acme.test/admin/billing/*excluded
Summary
- critical1
- high1
- medium2
- low1
- info1
Findings
F-001criticalCWE-639open
Order lookup returns other customers' orders
GET /api/orders/:id
The order endpoint checks that a session exists but not that the order belongs to it. Any customer can read any order by id.
Remediation. Scope the order query to the session's customer id, and return 404 for orders the session does not own.
F-002highCWE-918triaged
Avatar import fetches internal addresses
POST /api/users/:id/avatar
The avatar import fetches the supplied URL from the server without restricting the destination.
Remediation. Resolve the host first and reject private, loopback, and link-local ranges. Better: accept uploads instead of URLs.
F-003mediumCWE-614open
Session cookie lacks Secure and SameSite
POST /login
The session cookie is set without the Secure or SameSite attributes.
Remediation. Set Secure, HttpOnly, and SameSite=Lax on the session cookie.
F-004mediumCWE-79open
Search query reflected unencoded in error page
GET /search
When search fails, the 500 page echoes the q parameter into the HTML without encoding it.
Remediation. Encode q on output in the error template, and add a Content-Security-Policy.
F-005lowCWE-209fixed
Stack traces on malformed JSON
POST /api/orders
Malformed request bodies return a full Express stack trace with file paths.
Remediation. Return a generic error body in production.
F-006infoCWE-200open
Server versions in response headers
*
Server and X-Powered-By headers name nginx 1.25.3 and Express.
Remediation. Remove X-Powered-By and set server_tokens off.