Sample report · Web & mobile application assessment

Web & Mobile Application Assessment

A security assessment of web and mobile applications and their supporting APIs — the business-logic and access-control flaws a scanner never reaches.

What happened

By manipulating identifiers in API requests, OSec read other users’ account data and balances; the MFA flow allowed full API access before the second factor was ever completed. One high-risk finding, five medium.

Scope. Web and mobile applications and the APIs behind them — access control, session handling, and client-side protections.

What’s inside

The report, section by section

  1. Executive summary
  2. Scope
  3. Methodology
  4. Findings summary
  5. Findings (with reproduction)
  6. Conclusion

The findings

  • MFA bypass
  • Insecure direct object reference (IDOR)
  • Bypass of session security controls
  • Sensitive information disclosure
  • Account enumeration using application error
  • Unsanitised file upload

Client names, dates, hosts and other identifying details are redacted throughout. Everything else — findings, severity, method, and the walkthrough — is exactly as delivered.

The document

Read the full redacted report.

Take the PDF with you ↓

PDF not showing? Get a downloadable copy →

Take it with you

Get the PDF, plus all three sample reports.

You’ve read it here. Drop your email and we’ll send this report, plus the other two, as downloadable PDFs.

We’ll email the download links to that address.

Book a 30-min call