What our report looks like.
This is a redacted sample report run against OWASP Juice Shop — a deliberately vulnerable practice application built for training. It shows the structure, depth and tone of a real DebugSol engagement. It contains no real client data; every finding is from the practice app.
The assessment of the target web application (OWASP Juice Shop, a practice target) identified 6 findings: 1 critical, 2 high, 2 medium and 1 low. The critical and high issues allow authentication bypass, access to other users' data, and script injection — enough for an attacker to take over accounts and read customer records. All are fixable with standard controls. A retest is included once fixes are in place.
Findings · sample
The findings table.
| Severity | Finding | Status |
|---|---|---|
| Critical | SQL injection in login bypasses authentication | Open |
| High | Broken access control (IDOR) exposes other users' baskets | Open |
| High | Stored/DOM cross-site scripting in product search | Open |
| Medium | Sensitive files exposed under /ftp (confidential docs) | Open |
| Medium | Verbose error messages leak stack traces | Open |
| Low | Missing security headers (CSP, HSTS) | Open |
Detail · sample
One finding, in full.
SQL injection in login — Critical (CVSS 9.8)
Affected: POST /rest/user/login
Description: The login endpoint builds its SQL query by string-concatenating the email field. Supplying ' OR 1=1-- as the email logs an attacker in as the first user (the administrator) with no password.
Evidence (masked): request body {"email":"' OR 1=1--","password":"x"} → 200 OK with a valid admin session token.
Impact: Full authentication bypass and administrator access — total compromise of accounts and data.
Fix: Use parameterised queries / an ORM for all authentication logic; never concatenate user input into SQL. Add input validation and generic error messages.
Sample finding from OWASP Juice Shop — a deliberately vulnerable practice app.
Download the full sample report (PDF)
The full report includes every finding in this detail, the methodology, the severity model and the retest certificate. Enter your email and we'll unlock the download.
Download the sample report →Email only — no account, no spam. The PDF unlocks instantly; we'll only use your email to follow up and, occasionally, send a helpful security tip you can unsubscribe from.
Ready for a real one?
Fixed price, reported in days, retest included.