Mendix App Security Testing

Job ID: 39748797

Budget: €30 – €250 EUR

Apps: 3 Mendix applications → Purchase Request, Task Tracker, Coffee Service.

Tests Required:

SAST → via SonarQube (already Docker-ready).

DAST → via OWASP ZAP (active + passive scan).

RBAC & IDOR checks → screenshots proving unauthorized access attempts.

API security testing → using Postman or Burp Suite.


Deliverables:

Security artefact folder containing:

ZAP HTML reports (e.g., zap-purchase-passive.html).

SonarQube SAST results.

Screenshots for RBAC, IDOR, API tests.

A risk analysis report mapped to OWASP Top 10.

Suggested countermeasures.





this is urgent and must be delivered within 3 days

> Build an LCNC Security Artefact (SAST + DAST + API Testing) for Mendix Apps — 3-Day Delivery

Scope of Work:

1. SAST Testing

Use SonarQube (Docker-based) to analyze code for vulnerabilities.

Export HTML/PDF report.



2. DAST Testing

Use OWASP ZAP to perform passive + active scans on the running apps.

Generate individual ZAP reports for each app.



3. RBAC & IDOR Testing

Attempt unauthorized access by role switching.

Capture screenshots showing failures or bypasses.



4. API Security Testing

Use Postman/Burp Suite to test exposed REST endpoints.

Document findings with screenshots.



5. Final Artefact Deliverables:

/reports folder:

zap-purchase-passive.html

zap-tasktracker-passive.html

zap-coffee-passive.html

SonarQube SAST results


/screenshots folder:

RBAC test evidence

IDOR exploitation evidence

API test evidence


Risk Analysis PDF:

Map findings to OWASP Top 10.

Include countermeasures for each risk.





Requirements:

Experience with OWASP ZAP, SonarQube, Postman/Burp Suite.

Familiarity with low-code/no-code (LCNC) app testing.

Must deliver complete artefact + reports within 3 days.