CipherTest
boot sequence
loading offensive platform0%
CipherTest
Back to case studies
SaaS 4 weeks

Web Application Penetration Testing

Web Application Security Review

A high-growth SaaS platform engaged CipherTest to validate the security of a new customer portal before a major release. Manual testing uncovered a privilege-escalation chain that would have exposed tenant data.

Engagement scope: 1 customer portal, 3 admin surfaces, 2 public APIs
14Findings
2Critical
9 daysRemediation

Engagement Objectives

  • Validate multi-tenant isolation before GA launch
  • Assess authentication and session handling
  • Verify admin-surface access controls

Approach

We began with a scoping workshop to align on in-scope assets, rules of engagement, and success criteria. Over the following weeks, our consultants applied a manual-first methodology aligned to Web Application Penetration Testing, validating every finding before reporting and coordinating closely with the client's engineering team.

Outcome

We identified a cross-tenant access-control flaw and two authentication weaknesses. The engineering team remediated all findings before launch, and our free retest confirmed closure.

What We Delivered

Executive summary for leadership
Technical report with reproducible PoCs
CVSSv3.1 scored findings
Remediation walkthrough with engineers
Attack-path visualization
Free retest to confirm closure