Skip to content
Sample report

A complete report, with nothing real in it.

This is what a CyberZ report looks like. The company, systems, findings and dates are invented for demonstration. No real customer information is used anywhere on this page.

Sample / fictional data
Report
Web Application & API Penetration Test
Client
Example Company Inc. (fictional)
Report ID
CYZ-RPT-DEMO-0001
Version
1.1 (final, including retest results)
Testing
August 4 – August 15, 2026
Retest
September 2, 2026
Issued
September 3, 2026
01 · Executive summarySample / fictional data

CyberZ performed an independent penetration test of the Example Company web application and API between August 4 and August 15, 2026. Testing was authenticated and covered four roles across two tenants.

Six findings were identified: one Critical, one High, two Medium, one Low and one Informational. The Critical and High findings allowed cross-tenant access to customer data and were communicated to Example Company during testing. Both were remediated and verified during the retest on September 2, 2026.

Overall, the application's authentication and session handling were implemented soundly. The most significant weaknesses were in object-level authorization on the API and in a business-logic flaw in the invitation flow. At the time of the retest, no Critical or High severity findings remained open within the defined scope.

02 · Risk summary

Findings by severity, before and after retest.

SeverityIdentifiedOpen after retest
Critical10
High10
Medium21
Low10
Info11
03 · Scope

Two tenants were provisioned with four roles each; testing was performed authenticated and unauthenticated.

In scope

  • https://app.example-app.test (web application, tenant roles: Owner, Admin, Member, Viewer)
  • https://api.example-app.test/v1 (REST API used by the web and mobile clients)
  • Staging environment mirroring production, seeded with synthetic data

Out of scope

  • Third-party payment provider and its hosted pages
  • Corporate IT network and employee endpoints
  • Denial-of-service and resource exhaustion testing
04 · Methodology & limitations

Testing followed the OWASP Web Security Testing Guide, used the OWASP Application Security Verification Standard as a coverage reference and the OWASP API Security Top 10 for API-specific risks. Findings were scored with CVSS v4.0 base metrics and adjusted for context where noted. The exact test cases were adapted to the agreed scope.

Limitations

  • Testing was performed against a staging environment; configuration differences from production may exist.
  • Time-boxed to nine testing days; coverage prioritized authorization, tenancy and business logic per the agreed scope.
  • Rate limiting on the password reset endpoint was assessed without exceeding the agreed request volume.
  • This report reflects a point-in-time assessment of the stated scope.
05 · Findings

Six findings, ordered by severity.

Sample / fictional data
  1. CYZ-DEMO-001Sample / fictional data
    CriticalCVSS 9.1

    Cross-tenant read access to project exports via unvalidated export identifier

    Affected asset
    GET /v1/exports/{exportId}/download
    Description
    The export download endpoint validated that the caller was authenticated but did not verify that the requested export belonged to the caller's tenant. Export identifiers were sequential integers.
    Technical impact
    Any authenticated user could download data exports (CSV) generated by other tenants by iterating identifiers.
    Business impact
    Bulk exposure of customer data across tenants; likely contractual breach and notification obligations.
    Evidence (redacted, fictional)
    GET /v1/exports/20417/download HTTP/2Authorization: Bearer <tenant-A member token>HTTP/2 200 OKContent-Disposition: attachment; filename="projects-tenant-B.csv"

    Reproduction steps

    1. 1.Authenticate as a Member of tenant A and create an export; note the returned exportId (e.g. 20418).
    2. 2.Request /v1/exports/20417/download with the same token.
    3. 3.Observe a 200 response with a file belonging to a different tenant.

    Remediation

    • Enforce tenant ownership on export lookup server-side (WHERE tenant_id = caller.tenant_id).
    • Use random, non-sequential identifiers (UUIDv4 or similar) for exports as defense in depth.
    • Add an automated authorization test for this endpoint.

    Retest result

    Remediated

    Ownership check added; cross-tenant requests now return 404. Verified on September 2, 2026.

  2. CYZ-DEMO-002Sample / fictional data
    HighCVSS 8.1

    Privilege escalation to Admin via invitation role tampering

    Affected asset
    POST /v1/invitations/accept
    Description
    The invitation acceptance request included the invited role as a client-supplied field. The server trusted this value instead of the role stored with the invitation.
    Technical impact
    A user invited as Viewer could accept the invitation with role=admin and obtain Admin privileges in the tenant.
    Business impact
    Unauthorized administrative access to tenant settings, billing details and member management.
    Evidence (redacted, fictional)
    POST /v1/invitations/accept HTTP/2{"token":"inv_3f9…","role":"admin"}HTTP/2 200 OK  {"membership":{"role":"admin"}}

    Reproduction steps

    1. 1.As tenant Owner, invite a new user with role Viewer.
    2. 2.Intercept the acceptance request from the invited user and change role to admin.
    3. 3.Observe the resulting membership has the Admin role.

    Remediation

    • Ignore client-supplied role on acceptance; derive the role from the stored invitation record.
    • Reject requests containing unexpected fields for this endpoint.

    Retest result

    Remediated

    Role is now read from the invitation record only; tampered requests are rejected with 400.

  3. CYZ-DEMO-003Sample / fictional data
    MediumCVSS 5.3

    Password reset tokens valid for 24 hours and not invalidated on use

    Affected asset
    POST /v1/auth/password/reset
    Description
    Reset tokens remained valid for 24 hours and could be reused after a successful reset.
    Technical impact
    A leaked or intercepted reset link retains value for an extended window and can be replayed.
    Business impact
    Increased account takeover risk if reset emails are exposed through forwarding, logging or a compromised mailbox.
    Evidence (redacted, fictional)
    POST /v1/auth/password/reset  (same token, second use)HTTP/2 200 OK  {"status":"password_updated"}

    Reproduction steps

    1. 1.Request a reset link and complete the reset.
    2. 2.Submit the same token again with a new password.
    3. 3.Observe the second reset succeeds.

    Remediation

    • Invalidate reset tokens on first use.
    • Reduce token lifetime to 15–60 minutes.
    • Invalidate existing sessions on password change (already implemented).

    Retest result

    Remediated

    Tokens are single-use and expire after 30 minutes.

  4. CYZ-DEMO-004Sample / fictional data
    MediumCVSS 5.3

    GraphQL introspection and unbounded query depth on internal reporting endpoint

    Affected asset
    POST /v1/reporting/graphql
    Description
    Introspection was enabled and no depth or complexity limits were enforced; deeply nested queries increased response times significantly.
    Technical impact
    Full schema disclosure and a resource-consumption vector for authenticated users.
    Business impact
    Degraded reporting performance for all tenants under abusive queries; schema exposure aids further attacks.
    Evidence (redacted, fictional)
    query { projects { members { projects { members { … } } } } }  → 8.4s

    Reproduction steps

    1. 1.Send an introspection query and observe the full schema.
    2. 2.Send a query nested 12 levels deep and measure response time.

    Remediation

    • Disable introspection in production.
    • Enforce query depth and complexity limits.
    • Apply per-user rate limits to the endpoint.

    Retest result

    Partially remediated

    Introspection disabled; depth limit of 8 enforced. Complexity limit scheduled for a later release.

  5. CYZ-DEMO-005Sample / fictional data
    LowCVSS 3.1

    Verbose error responses reveal framework and stack trace details

    Affected asset
    https://api.example-app.test/v1/* (malformed JSON bodies)
    Description
    Malformed JSON bodies produced stack traces including internal file paths and framework version.
    Technical impact
    Information useful for targeting known vulnerabilities in the identified components.
    Business impact
    Low direct impact; contributes to attacker reconnaissance.
    Evidence (redacted, fictional)
    HTTP/2 500  {"error":"SyntaxError: Unexpected token…","stack":"/srv/api/…"}

    Reproduction steps

    1. 1.Send a request with an invalid JSON body to any POST endpoint.
    2. 2.Observe stack trace in the response.

    Remediation

    • Return generic error messages in production; log details server-side only.

    Retest result

    Remediated

    Generic error handler deployed.

  6. CYZ-DEMO-006Sample / fictional data
    InfoNo CVSS score

    Content-Security-Policy not enforced on the web application

    Affected asset
    https://app.example-app.test
    Description
    No Content-Security-Policy header was present. No exploitable XSS was identified during testing; CSP is recommended as defense in depth.
    Technical impact
    Reduced mitigation should a script injection vulnerability be introduced in the future.
    Business impact
    None directly observed.
    Evidence (redacted, fictional)
    GET / → headers: no content-security-policy

    Reproduction steps

    1. 1.Inspect response headers on any application page.

    Remediation

    • Deploy a nonce-based CSP with strict-dynamic; start in report-only mode.

    Retest result

    Open

    Planned; report-only policy in progress.

06 · Remediation recommendations
  1. 01Centralize tenant and object ownership checks in a single authorization layer used by every API handler.
  2. 02Add authorization tests to the CI pipeline for each endpoint that accepts an object identifier.
  3. 03Treat invitations and role changes as security-sensitive workflows with explicit state validation.
  4. 04Retain the current session and MFA implementation; consider shortening refresh token lifetime as defense in depth.
07 · Retest results

Retest performed September 2, 2026.

IDSeverityStatus
CYZ-DEMO-001CriticalRemediated
CYZ-DEMO-002HighRemediated
CYZ-DEMO-003MediumRemediated
CYZ-DEMO-004MediumPartially remediated
CYZ-DEMO-005LowRemediated
CYZ-DEMO-006InfoOpen

Security assessments represent a point-in-time evaluation and do not constitute a guarantee that the assessed systems remain secure or free from vulnerabilities after the assessment. This sample is provided to illustrate report structure and quality only.

Next step

Get a report like this for your own application.

Tell us what you need tested, when, and which evidence you need at the end. We reply with scoping questions, not a sales deck.