Sample report
Know exactly what you'll receive.
A report is only useful if someone can act on it. Below is the real structure of a PXL Security penetration-test report — cover, contents, executive summary, scope, methodology, a summary-of-findings table and fully-detailed findings — with anonymised examples drawn from real engagements. The deliverable is a formatted PDF, walked through in a live debrief.
Penetration Test Report
Web Application & API Security Assessment
Prepared for [Client] by PXL Security LTD
1 Executive summary
PXL Security LTD was engaged to perform a manual, objective-driven penetration test of the in-scope web application and its supporting API. Testing was conducted by senior engineers and followed recognised methodology (OWASP WSTG, PTES). This summary is written for a non-technical audience; technical detail follows in Section 6.
The assessment identified 9 findings: 2 critical, 3 high, 3 medium and 1 low. The critical and high-severity issues centre on credential handling, access control and authentication, and together could lead to compromise of customer data or of the wider environment. None required novel exploitation — they stem from configuration and design choices that are straightforward to correct. A complimentary retest is included to verify remediation.
Overall risk rating: High — driven by the credential-handling and access-control findings, which are individually exploitable and together chainable.
2 Engagement scope
| Target | Customer-facing web application and supporting REST API ([Client] production/staging as agreed) |
|---|---|
| Assessment type | Grey-box, authenticated (multiple roles) |
| Testing window | [Agreed dates] · business hours, with emergency contacts on call |
| Standards | OWASP WSTG & API Top 10, PTES, CVSS v3.1 |
| Exclusions | Denial-of-service and physical testing (out of scope by agreement) |
3 Methodology
Testing followed our standard five-stage approach: scope & threat-model, reconnaissance & mapping, manual exploitation, reporting, and a complimentary retest. Automated tooling was used for coverage and speed; every reported finding was manually verified and, where safe, exploited to demonstrate genuine impact. Full methodology is on our How we work page.
4 Severity ratings
Findings are rated on business risk, informed by CVSS v3.1 and the real exploitability and impact in your environment.
| Rating | Meaning |
|---|---|
| Critical | Immediate, severe business impact; exploit is straightforward. Fix now. |
| High | Significant impact; realistic to exploit. Fix in the current cycle. |
| Medium | Moderate impact or harder to exploit. Plan remediation. |
| Low | Limited impact; hardening or defence-in-depth. |
5 Summary of findings
| ID | Finding | Severity | Status |
|---|---|---|---|
F-01 | Hardcoded backend credentials in a shipped mobile app | Critical | Open |
F-02 | Application database account is a cluster superuser | Critical | Open |
F-03 | Production session-signing key recoverable from the app host | High | Open |
F-04 | Kerberoastable Domain Admin service account, password unchanged for years | High | Open |
F-05 | Internet-facing remote-access gateway on an end-of-life OS | High | Open |
F-06 | Long-lived API token leaked via URL fragment and JavaScript global | Medium | Open |
F-07 | Stored spreadsheet formula injection in data export | Medium | Open |
Seven of nine findings are detailed below as examples; the full report details every finding. All are anonymised and drawn from real engagements.
6 Detailed findings
F-01 Hardcoded backend credentials in a shipped mobile app
- Severity
- Critical · CVSS 9.1 (illustrative)
- Affected
Mobile app bundle- Description
- Reverse-engineering the binary yielded working credentials that granted a live, authenticated session to an internal customer-data API.
- Evidence
- Request/response pair and annotated screenshots provided in Appendix A of the full report.
- Reproduction
- Step-by-step reproduction is included in the full report so your engineers can confirm the issue.
- Recommendation
- Remove all embedded credentials, broker authentication server-side via SSO/OAuth, and rotate the exposed accounts.
F-02 Application database account is a cluster superuser
- Severity
- Critical · CVSS 9.1 (illustrative)
- Affected
App-to-database connection- Description
- A compromised application process gained read/write across every tenant database and command execution on the database host.
- Evidence
- Request/response pair and annotated screenshots provided in Appendix A of the full report.
- Reproduction
- Step-by-step reproduction is included in the full report so your engineers can confirm the issue.
- Recommendation
- Demote the account to least privilege and network-restrict the database to its application hosts only.
F-03 Production session-signing key recoverable from the app host
- Severity
- High · CVSS 8.1 (illustrative)
- Affected
Web session / token signing- Description
- The key allowed offline forgery of a valid session for any user, role or tenant, with no authentication.
- Evidence
- Request/response pair and annotated screenshots provided in Appendix A of the full report.
- Reproduction
- Step-by-step reproduction is included in the full report so your engineers can confirm the issue.
- Recommendation
- Move signing keys into a secrets manager or HSM out of app-readable storage, and rotate immediately.
F-04 Kerberoastable Domain Admin service account, password unchanged for years
- Severity
- High · CVSS 8.1 (illustrative)
- Affected
Active Directory service account- Description
- Any authenticated user could request a crackable ticket for a full domain-admin credential.
- Evidence
- Request/response pair and annotated screenshots provided in Appendix A of the full report.
- Reproduction
- Step-by-step reproduction is included in the full report so your engineers can confirm the issue.
- Recommendation
- Rotate to a strong random password or a group-managed service account, and remove it from Domain Admins.
F-05 Internet-facing remote-access gateway on an end-of-life OS
- Severity
- High · CVSS 8.1 (illustrative)
- Affected
External authentication gateway- Description
- An out-of-support OS acting as an AD authentication boundary exposed the perimeter to unpatched flaws and leaked internal domain and host names.
- Evidence
- Request/response pair and annotated screenshots provided in Appendix A of the full report.
- Reproduction
- Step-by-step reproduction is included in the full report so your engineers can confirm the issue.
- Recommendation
- Migrate the role to a supported, patched platform and suppress internal-name disclosure.
F-06 Long-lived API token leaked via URL fragment and JavaScript global
- Severity
- Medium · CVSS 6.4 (illustrative)
- Affected
SSO handoff / single-page app- Description
- A 24-hour data-API token landed in browser history and page scripts and was not revoked on logout, widening the window for theft and reuse.
- Evidence
- Request/response pair and annotated screenshots provided in Appendix A of the full report.
- Reproduction
- Step-by-step reproduction is included in the full report so your engineers can confirm the issue.
- Recommendation
- Use authorization-code + PKCE, keep tokens out of URLs and globals, shorten lifetimes and revoke server-side.
F-07 Stored spreadsheet formula injection in data export
- Severity
- Medium · CVSS 6.4 (illustrative)
- Affected
Table / CSV export- Description
- User-supplied fields were written as live formulas that execute on the workstation of whoever opens the export.
- Evidence
- Request/response pair and annotated screenshots provided in Appendix A of the full report.
- Reproduction
- Step-by-step reproduction is included in the full report so your engineers can confirm the issue.
- Recommendation
- Escape leading =, +, -, @ characters and force string cell types on every export.
7 Retest & closure
Once your team has remediated, we re-test every finding and reissue the report with an updated status (Closed / Partially remediated / Open) and a signed closure letter you can share with customers and auditors — included as standard, at no extra cost.
Want the real thing for your systems?
Send a short description of your environment and goals. A senior tester, not a salesperson, will reply with questions, a proposed approach and a quote.