DebugSol
Sample · not a real client

What our report looks like.

This is a redacted sample report run against OWASP Juice Shop — a deliberately vulnerable practice application built for training. It shows the structure, depth and tone of a real DebugSol engagement. It contains no real client data; every finding is from the practice app.

Executive summary · sample

The assessment of the target web application (OWASP Juice Shop, a practice target) identified 6 findings: 1 critical, 2 high, 2 medium and 1 low. The critical and high issues allow authentication bypass, access to other users' data, and script injection — enough for an attacker to take over accounts and read customer records. All are fixable with standard controls. A retest is included once fixes are in place.

Findings · sample

The findings table.

SeverityFindingStatus
Critical SQL injection in login bypasses authentication Open
High Broken access control (IDOR) exposes other users' baskets Open
High Stored/DOM cross-site scripting in product search Open
Medium Sensitive files exposed under /ftp (confidential docs) Open
Medium Verbose error messages leak stack traces Open
Low Missing security headers (CSP, HSTS) Open

Detail · sample

One finding, in full.

SQL injection in login — Critical (CVSS 9.8)

Affected: POST /rest/user/login

Description: The login endpoint builds its SQL query by string-concatenating the email field. Supplying ' OR 1=1-- as the email logs an attacker in as the first user (the administrator) with no password.

Evidence (masked): request body {"email":"' OR 1=1--","password":"x"} → 200 OK with a valid admin session token.

Impact: Full authentication bypass and administrator access — total compromise of accounts and data.

Fix: Use parameterised queries / an ORM for all authentication logic; never concatenate user input into SQL. Add input validation and generic error messages.

Sample finding from OWASP Juice Shop — a deliberately vulnerable practice app.

Download the full sample report (PDF)

The full report includes every finding in this detail, the methodology, the severity model and the retest certificate. Enter your email and we'll unlock the download.

Email only — no account, no spam. The PDF unlocks instantly; we'll only use your email to follow up and, occasionally, send a helpful security tip you can unsubscribe from.

Ready for a real one?

Fixed price, reported in days, retest included.