Complete redacted sample

Web application pentest sample report

A complete customer-safe illustrative report showing the technical depth, executive context and remediation guidance included in a LunarChain Security web application and API assessment.

Findings snapshot

High

The sample application contains eight chainable web and API weaknesses, led by broken object-level authorisation that permits cross-tenant record access.

1 critical4 high2 medium1 low

Key findings

  • Broken object-level authorisation on transaction APIs
  • Mass-assignment privilege escalation through unsafe object binding
  • Stored XSS leading to support-console session compromise
  • SSRF through webhook configuration reaching cloud metadata
  • Password reset tokens remaining valid after reuse and extended lifetime

Report structure

Executive summary

A plain-English risk narrative, severity counts, business impact and the first fixes leadership should prioritise.

Scope and methodology

Targets, credentials, exclusions, rules of engagement and the manual testing approach used during the assessment.

Attack narrative

A step-by-step chain showing how separate weaknesses combine into tenant compromise and platform administration.

Technical findings

Per-finding evidence, affected systems, CVSS scoring, impact, reproduction detail and concrete remediation guidance.

Strategic recommendations

Prioritised engineering and governance actions that reduce the highest-risk attack paths first.

Appendices

Evidence references, standards mapping, scope details and retest notes for audit and engineering handover.

Methodology

Evidence built for engineers, auditors and leadership

Each sample is deliberately illustrative and customer-safe. The structure mirrors a live engagement: agreed scope, manual verification, evidence references, remediation guidance and retest-ready status tracking.

Book a call

Methods and standards

OWASP WSTGOWASP API Security Top 10PTESNIST SP 800-115

Relevant services

Choose when your next test starts.

Standard within 10 business days. Rapid as soon as the next business day.

Book a call