Our competitors hide their deliverables behind sales calls. This is an anonymized real engagement report — the same format, depth, and quality you'll receive on day one of a ZDS engagement.
ANONYMIZED REAL ENGAGEMENT — REDACTED FOR DISCLOSUREZero Delta Security conducted a black-box web application penetration test of the client's primary e-commerce platform between March 10–14, 2025. The engagement targeted authentication, session management, input handling, access controls, and API endpoints in scope as defined by the client.
The assessment identified 11 findings across the severity spectrum, including one Critical vulnerability (SQL Injection in the login endpoint) that would allow an unauthenticated attacker to extract the full customer database, bypass authentication entirely, and potentially escalate to remote code execution on the underlying server. This finding requires immediate remediation.
Additionally, a High-severity broken access control vulnerability allows any authenticated user to elevate privileges to an administrative role by modifying a single JWT claim. This finding was validated end-to-end and confirmed to grant full admin panel access to arbitrary user accounts.
The two Medium-severity findings — a reflected XSS in the search function and weak TLS configuration — represent meaningful risk, particularly the XSS given the platform handles payment data. The Low and Informational findings are documented for completeness and should be addressed in the normal patch cadence.
Overall security posture: Needs Immediate Attention. The Critical and High findings must be remediated before this system processes production traffic. We estimate both can be resolved within 1–2 engineering sprints with the guidance provided in Section 4.
Findings are plotted by Likelihood (probability of exploitation) vs Impact (business consequence if exploited). Risk score drives remediation priority independent of CVSS.
| Negligible | Minor | Moderate | Significant | Catastrophic | |
|---|---|---|---|---|---|
| Certain | MED | HIGH | HIGH | CRIT ZDS-001 |
CRIT |
| Likely | LOW | MED | HIGH ZDS-002 |
CRIT | CRIT |
| Possible | INFO | LOW | MED ZDS-003/004 |
HIGH | CRIT |
| Unlikely | INFO | INFO | LOW | MED | HIGH |
↑ Likelihood axis (rows) · → Impact axis (columns)
Remediation items sequenced by risk priority. Sprint estimate assumes a 2-engineer team. Effort rating: ● = 0.5 days, ●●● = 1.5 days, ●●●●● = 3+ days.
| ID | Finding | Priority | Sprint | Effort | Owner |
|---|---|---|---|---|---|
| ZDS-001 | SQL Injection — Auth Endpoint | P1 — Immediate | Sprint 1 | Backend Dev | |
| ZDS-002 | JWT Role Escalation | P1 — Immediate | Sprint 1 | Backend Dev | |
| ZDS-003 | Reflected XSS — Search | P2 — High | Sprint 1–2 | Frontend Dev | |
| ZDS-004 | Weak TLS Configuration | P2 — High | Sprint 2 | DevOps / Infra | |
| ZDS-005–007 | Low severity findings (3 items) | P3 — Medium | Sprint 3 | Backend Dev | |
| ZDS-008–011 | Informational items (4 items) | P4 — Low | Backlog | Any dev |
Enter your email and we'll send you the full sample report in PDF format — plus a free consultation on what a ZDS engagement would uncover for your business.
No spam. No sales pressure. Unsubscribe anytime.
Check your inbox — we've sent the PDF and a link to schedule your free attack surface assessment.
No commitment, no credit card. Understand your exposure in under 5 minutes.