One flaw exposed every support conversation
What did an online platform pentest reveal?
SPIREE Case Study | White-box testing of a web platform managing user accounts and financial operations
As part of an authorized penetration test, we assessed a web platform where safeguarding user data and securing administrative functions were of paramount importance. The test was conducted using a white-box approach, allowing us to evaluate not only the external interface but also the APIs, access control mechanisms, selected cloud environment configurations, code repository, and the setup of the test environment.
What did we want to verify?
Collaborating closely with the client's team, we defined a scope focused on the platform's core areas. Among other aspects, we verified whether:
access to data and functionalities is properly restricted,
APIs require valid authentication and enforce permissions correctly,
cloud storage resources containing data are not publicly accessible,
secrets and tokens are handled securely,
session configuration and authentication support robust account protection,
the staging environment does not expose unnecessary diagnostic features.
What did we find?
The test revealed 16 vulnerabilities and weaknesses: one critical, five high, three medium, and five low-risk issues, along with two informational findings.
The most critical issue involved access control: it was possible to gain unauthorized access to all user conversations with the support team.
We also identified five high-risk vulnerabilities:
the ability to bypass the protection layer and reach the API directly,
a lack of permission controls on specific administrative endpoints,
public accessibility of a cloud data storage resource,
exposure of administrative data without the required authentication,
secrets and tokens hardcoded in the repository.
The remaining findings included:
Medium risk: exposed source maps, insecure session cookie configuration, and potential supply chain risks.
Low risk: lack of validation for withdrawal addresses, inconsistent enforcement of two-factor authentication, missing security headers, excessive data exposure, and the use of a vulnerable framework library version.
Informational findings: accessible diagnostic endpoints in the staging environment and vulnerable external dependencies.
Why did these findings matter?
Several issues directly affected access boundaries: who can read conversations, download data, or use administrative functions. Others related to protecting accounts and secrets, or ensuring that resources and interfaces are restricted to authorized users and systems.
A combination of such weaknesses can increase the risk of data breaches, unauthorized actions in admin panels, and the exploitation of compromised tokens or configuration errors. The report detailed these findings alongside their risk levels, helping the team prioritize remediation effectively.
What are the benefits of a white-box test?
A white-box test allows us to analyze a solution with deeper insight into its architecture and inner workings. This enables an assessment that goes beyond what is visible from the outside, covering authorization mechanisms, APIs, configuration, and specific code components or dependencies.
In this project, this approach helped detect issues across various layers of the platform—from access controls on user chat logs and administrative endpoints, to secrets stored in the repository and cloud resources.
Key Takeaways
The most significant risks do not always stem from a single, complex vulnerability. Often, the critical weak point is a simple lack of access control where user data intersects with operational platform features. This is why testing should evaluate data and permission flows across the entire solution, rather than focusing on a single screen or URL.
SPIREE delivers thorough penetration testing for applications, APIs, and infrastructure. We tailor the scope to your product's architecture and your specific validation goals prior to deployment, audit, or your next phase of growth.
Would you like to see how your platform performs from the perspective of a potential attacker? Let's discuss the scope of your test.
This version does not attribute fix implementations or positive retest results to the client, as this information was not included in the provided test summary.