1. Scope and authorisation

Client
Northwind Retail (fictional)
Reference
PS-DEMO-0142
Scope
https://demo.northwind-retail.example — public storefront and customer account area
Test window
12–18 March, authorised in writing by the site owner
Performed by
ProSphere assessment team

2. Executive summary

Ten findings were identified during the assessment window. Two are critical and require immediate attention: unrestricted login attempts and order records reachable by changing an identifier. Three high-severity items relate to stored script injection, session cookie configuration and password reset handling. The remaining findings are configuration and hygiene issues that reduce defence in depth. None of the issues required privileged access to discover, and all were confirmed with non-destructive testing.

2

Critical

3

High

2

Medium

2

Low

1

Informational

3. Findings

PS-001CriticalOpenP1

Login form accepts unlimited password attempts

Affected area
/account/login
Evidence
500 sequential attempts from a single address returned no lockout, delay or challenge.
Impact
An attacker can guess weak customer passwords at scale and take over accounts.
Remediation
Add progressive delays, account lockout after repeated failures and a challenge after 5 attempts.
PS-002CriticalIn progressP1

Order details reachable by changing the order number

Affected area
/account/orders/{id}
Evidence
A signed-in test account could load orders belonging to a second test account by editing the id.
Impact
Customer names, addresses and purchase history are exposed to other signed-in users.
Remediation
Check ownership of the order server-side before returning any order data.
PS-003HighRetestP1

Stored script injection in product review field

Affected area
/product/{slug} — review submission
Evidence
A review containing a script payload was saved and executed when the product page was viewed.
Impact
Scripts run in other shoppers' browsers, enabling session theft or page manipulation.
Remediation
Encode output on render and validate review content on the server.
PS-004HighResolvedP2

Session cookie missing secure attributes

Affected area
Global — session cookie
Evidence
Session cookie issued without HttpOnly and SameSite attributes.
Impact
Session values are readable by scripts and can be sent on cross-site requests.
Remediation
Set HttpOnly, Secure and SameSite=Lax on all session cookies.
PS-005HighOpenP2

Password reset tokens do not expire

Affected area
/account/reset
Evidence
A reset link generated 9 days earlier was still accepted.
Impact
An old email in a compromised inbox remains a valid route into the account.
Remediation
Expire reset tokens after 30 minutes and invalidate them once used.
PS-006MediumIn progressP3

Verbose error page reveals framework and version

Affected area
/checkout — 500 handler
Evidence
An invalid payload returned a stack trace naming the framework, version and file paths.
Impact
Gives an attacker a precise target list of known issues for that version.
Remediation
Return a generic error page in production and log details server-side only.
PS-007MediumOpenP3

File upload accepts oversized and unexpected types

Affected area
/account/support — attachment
Evidence
A 90 MB archive was accepted with no type restriction applied.
Impact
Storage exhaustion and the risk of serving dangerous files back to users.
Remediation
Restrict to a defined type list, cap file size and store outside the web root.
PS-008LowResolvedP4

Missing security headers

Affected area
Global — HTTP responses
Evidence
No Content-Security-Policy, X-Content-Type-Options or Referrer-Policy headers present.
Impact
Reduces defence in depth against injection and data leakage through referrers.
Remediation
Add a baseline header set at the edge or in the application response layer.
PS-009LowRetestP4

Directory listing enabled on asset folder

Affected area
/assets/uploads/
Evidence
The folder index rendered a browsable list of uploaded files.
Impact
Files intended to be unlisted can be discovered and downloaded.
Remediation
Disable directory indexing and serve assets through explicit routes.
PS-010InformationalOpenP4

Outdated JavaScript dependency in checkout bundle

Affected area
Checkout bundle
Evidence
A bundled library is four minor versions behind current, with published fixes in between.
Impact
No exploit observed; carries avoidable future risk.
Remediation
Schedule a dependency update and add automated version monitoring.

4. Remediation and retesting

  1. Day 0

    Assessment complete

    10 findings documented and delivered.

  2. Day 2

    Walkthrough call

    Findings explained and priorities agreed with the team.

  3. Day 6

    First fixes shipped

    Cookie attributes and header baseline deployed.

  4. Day 9

    Retest round one

    Two findings verified as resolved, one returned for rework.

  5. Day 14

    Retest round two

    Remaining high-severity items scheduled with owners.

5. Testing conduct

All testing is non-destructive, performed inside the agreed window, and only on systems the client owns or is authorised in writing to test. No customer data is copied, retained or shared. Evidence is limited to the minimum needed to demonstrate a finding.