1. Scope and authorisation
- Client
- Northwind Retail (fictional)
- Reference
- PS-DEMO-0142
- Scope
- https://demo.northwind-retail.example — public storefront and customer account area
- Test window
- 12–18 March, authorised in writing by the site owner
- Performed by
- ProSphere assessment team
2. Executive summary
Ten findings were identified during the assessment window. Two are critical and require immediate attention: unrestricted login attempts and order records reachable by changing an identifier. Three high-severity items relate to stored script injection, session cookie configuration and password reset handling. The remaining findings are configuration and hygiene issues that reduce defence in depth. None of the issues required privileged access to discover, and all were confirmed with non-destructive testing.
2
Critical
3
High
2
Medium
2
Low
1
Informational
3. Findings
Login form accepts unlimited password attempts
- Affected area
- /account/login
- Evidence
- 500 sequential attempts from a single address returned no lockout, delay or challenge.
- Impact
- An attacker can guess weak customer passwords at scale and take over accounts.
- Remediation
- Add progressive delays, account lockout after repeated failures and a challenge after 5 attempts.
Order details reachable by changing the order number
- Affected area
- /account/orders/{id}
- Evidence
- A signed-in test account could load orders belonging to a second test account by editing the id.
- Impact
- Customer names, addresses and purchase history are exposed to other signed-in users.
- Remediation
- Check ownership of the order server-side before returning any order data.
Stored script injection in product review field
- Affected area
- /product/{slug} — review submission
- Evidence
- A review containing a script payload was saved and executed when the product page was viewed.
- Impact
- Scripts run in other shoppers' browsers, enabling session theft or page manipulation.
- Remediation
- Encode output on render and validate review content on the server.
Session cookie missing secure attributes
- Affected area
- Global — session cookie
- Evidence
- Session cookie issued without HttpOnly and SameSite attributes.
- Impact
- Session values are readable by scripts and can be sent on cross-site requests.
- Remediation
- Set HttpOnly, Secure and SameSite=Lax on all session cookies.
Password reset tokens do not expire
- Affected area
- /account/reset
- Evidence
- A reset link generated 9 days earlier was still accepted.
- Impact
- An old email in a compromised inbox remains a valid route into the account.
- Remediation
- Expire reset tokens after 30 minutes and invalidate them once used.
Verbose error page reveals framework and version
- Affected area
- /checkout — 500 handler
- Evidence
- An invalid payload returned a stack trace naming the framework, version and file paths.
- Impact
- Gives an attacker a precise target list of known issues for that version.
- Remediation
- Return a generic error page in production and log details server-side only.
File upload accepts oversized and unexpected types
- Affected area
- /account/support — attachment
- Evidence
- A 90 MB archive was accepted with no type restriction applied.
- Impact
- Storage exhaustion and the risk of serving dangerous files back to users.
- Remediation
- Restrict to a defined type list, cap file size and store outside the web root.
Missing security headers
- Affected area
- Global — HTTP responses
- Evidence
- No Content-Security-Policy, X-Content-Type-Options or Referrer-Policy headers present.
- Impact
- Reduces defence in depth against injection and data leakage through referrers.
- Remediation
- Add a baseline header set at the edge or in the application response layer.
Directory listing enabled on asset folder
- Affected area
- /assets/uploads/
- Evidence
- The folder index rendered a browsable list of uploaded files.
- Impact
- Files intended to be unlisted can be discovered and downloaded.
- Remediation
- Disable directory indexing and serve assets through explicit routes.
Outdated JavaScript dependency in checkout bundle
- Affected area
- Checkout bundle
- Evidence
- A bundled library is four minor versions behind current, with published fixes in between.
- Impact
- No exploit observed; carries avoidable future risk.
- Remediation
- Schedule a dependency update and add automated version monitoring.
4. Remediation and retesting
Day 0
Assessment complete
10 findings documented and delivered.
Day 2
Walkthrough call
Findings explained and priorities agreed with the team.
Day 6
First fixes shipped
Cookie attributes and header baseline deployed.
Day 9
Retest round one
Two findings verified as resolved, one returned for rework.
Day 14
Retest round two
Remaining high-severity items scheduled with owners.
5. Testing conduct
All testing is non-destructive, performed inside the agreed window, and only on systems the client owns or is authorised in writing to test. No customer data is copied, retained or shared. Evidence is limited to the minimum needed to demonstrate a finding.