PXL Security LTD, Sofia, Bulgaria Offensive security since 2014[email protected]

Sample report

Know exactly what you'll receive.

A report is only useful if someone can act on it. Below is the real structure of a PXL Security penetration-test report — cover, contents, executive summary, scope, methodology, a summary-of-findings table and fully-detailed findings — with anonymised examples drawn from real engagements. The deliverable is a formatted PDF, walked through in a live debrief.

CONFIDENTIAL

Penetration Test Report

Web Application & API Security Assessment

Prepared for [Client] by PXL Security LTD

Report reference
PXL-2026-0142
Version
1.0 (Final)
Date
[Engagement date]
Classification
Confidential

1   Executive summary

PXL Security LTD was engaged to perform a manual, objective-driven penetration test of the in-scope web application and its supporting API. Testing was conducted by senior engineers and followed recognised methodology (OWASP WSTG, PTES). This summary is written for a non-technical audience; technical detail follows in Section 6.

The assessment identified 9 findings: 2 critical, 3 high, 3 medium and 1 low. The critical and high-severity issues centre on credential handling, access control and authentication, and together could lead to compromise of customer data or of the wider environment. None required novel exploitation — they stem from configuration and design choices that are straightforward to correct. A complimentary retest is included to verify remediation.

Critical2
High3
Medium3
Low1

Overall risk rating: High — driven by the credential-handling and access-control findings, which are individually exploitable and together chainable.

2   Engagement scope

TargetCustomer-facing web application and supporting REST API ([Client] production/staging as agreed)
Assessment typeGrey-box, authenticated (multiple roles)
Testing window[Agreed dates] · business hours, with emergency contacts on call
StandardsOWASP WSTG & API Top 10, PTES, CVSS v3.1
ExclusionsDenial-of-service and physical testing (out of scope by agreement)

3   Methodology

Testing followed our standard five-stage approach: scope & threat-model, reconnaissance & mapping, manual exploitation, reporting, and a complimentary retest. Automated tooling was used for coverage and speed; every reported finding was manually verified and, where safe, exploited to demonstrate genuine impact. Full methodology is on our How we work page.

4   Severity ratings

Findings are rated on business risk, informed by CVSS v3.1 and the real exploitability and impact in your environment.

RatingMeaning
CriticalImmediate, severe business impact; exploit is straightforward. Fix now.
HighSignificant impact; realistic to exploit. Fix in the current cycle.
MediumModerate impact or harder to exploit. Plan remediation.
LowLimited impact; hardening or defence-in-depth.

5   Summary of findings

IDFindingSeverityStatus
F-01Hardcoded backend credentials in a shipped mobile appCriticalOpen
F-02Application database account is a cluster superuserCriticalOpen
F-03Production session-signing key recoverable from the app hostHighOpen
F-04Kerberoastable Domain Admin service account, password unchanged for yearsHighOpen
F-05Internet-facing remote-access gateway on an end-of-life OSHighOpen
F-06Long-lived API token leaked via URL fragment and JavaScript globalMediumOpen
F-07Stored spreadsheet formula injection in data exportMediumOpen

Seven of nine findings are detailed below as examples; the full report details every finding. All are anonymised and drawn from real engagements.

6   Detailed findings

Critical

F-01  Hardcoded backend credentials in a shipped mobile app

Severity
Critical · CVSS 9.1 (illustrative)
Affected
Mobile app bundle
Description
Reverse-engineering the binary yielded working credentials that granted a live, authenticated session to an internal customer-data API.
Evidence
Request/response pair and annotated screenshots provided in Appendix A of the full report.
Reproduction
Step-by-step reproduction is included in the full report so your engineers can confirm the issue.
Recommendation
Remove all embedded credentials, broker authentication server-side via SSO/OAuth, and rotate the exposed accounts.
Critical

F-02  Application database account is a cluster superuser

Severity
Critical · CVSS 9.1 (illustrative)
Affected
App-to-database connection
Description
A compromised application process gained read/write across every tenant database and command execution on the database host.
Evidence
Request/response pair and annotated screenshots provided in Appendix A of the full report.
Reproduction
Step-by-step reproduction is included in the full report so your engineers can confirm the issue.
Recommendation
Demote the account to least privilege and network-restrict the database to its application hosts only.
High

F-03  Production session-signing key recoverable from the app host

Severity
High · CVSS 8.1 (illustrative)
Affected
Web session / token signing
Description
The key allowed offline forgery of a valid session for any user, role or tenant, with no authentication.
Evidence
Request/response pair and annotated screenshots provided in Appendix A of the full report.
Reproduction
Step-by-step reproduction is included in the full report so your engineers can confirm the issue.
Recommendation
Move signing keys into a secrets manager or HSM out of app-readable storage, and rotate immediately.
High

F-04  Kerberoastable Domain Admin service account, password unchanged for years

Severity
High · CVSS 8.1 (illustrative)
Affected
Active Directory service account
Description
Any authenticated user could request a crackable ticket for a full domain-admin credential.
Evidence
Request/response pair and annotated screenshots provided in Appendix A of the full report.
Reproduction
Step-by-step reproduction is included in the full report so your engineers can confirm the issue.
Recommendation
Rotate to a strong random password or a group-managed service account, and remove it from Domain Admins.
High

F-05  Internet-facing remote-access gateway on an end-of-life OS

Severity
High · CVSS 8.1 (illustrative)
Affected
External authentication gateway
Description
An out-of-support OS acting as an AD authentication boundary exposed the perimeter to unpatched flaws and leaked internal domain and host names.
Evidence
Request/response pair and annotated screenshots provided in Appendix A of the full report.
Reproduction
Step-by-step reproduction is included in the full report so your engineers can confirm the issue.
Recommendation
Migrate the role to a supported, patched platform and suppress internal-name disclosure.
Medium

F-06  Long-lived API token leaked via URL fragment and JavaScript global

Severity
Medium · CVSS 6.4 (illustrative)
Affected
SSO handoff / single-page app
Description
A 24-hour data-API token landed in browser history and page scripts and was not revoked on logout, widening the window for theft and reuse.
Evidence
Request/response pair and annotated screenshots provided in Appendix A of the full report.
Reproduction
Step-by-step reproduction is included in the full report so your engineers can confirm the issue.
Recommendation
Use authorization-code + PKCE, keep tokens out of URLs and globals, shorten lifetimes and revoke server-side.
Medium

F-07  Stored spreadsheet formula injection in data export

Severity
Medium · CVSS 6.4 (illustrative)
Affected
Table / CSV export
Description
User-supplied fields were written as live formulas that execute on the workstation of whoever opens the export.
Evidence
Request/response pair and annotated screenshots provided in Appendix A of the full report.
Reproduction
Step-by-step reproduction is included in the full report so your engineers can confirm the issue.
Recommendation
Escape leading =, +, -, @ characters and force string cell types on every export.

7   Retest & closure

Once your team has remediated, we re-test every finding and reissue the report with an updated status (Closed / Partially remediated / Open) and a signed closure letter you can share with customers and auditors — included as standard, at no extra cost.

Appendices in the full report include per-finding evidence (requests, responses, annotated screenshots), the tooling used, and a machine-readable findings export (CSV/JSON) for your tracker.

Want the real thing for your systems?

Send a short description of your environment and goals. A senior tester, not a salesperson, will reply with questions, a proposed approach and a quote.

Prefer email? Write to [email protected]. We reply within one business day.