Greybox Web Shop Pen Test

Job ID: 40176379

Budget: €30 – €250 EUR

I need a greybox penetration test on our staging web shop. The assessment must cover three critical user flows—payment gateway, registration/login, and the product catalog—so I can pinpoint real-world vulnerabilities before we push to production.

The single overriding goal is to identify weaknesses, with special attention to anything that could lead to Cross-Site Scripting (XSS), but all other findings are welcome. I will provide a standard customer account, limited backend documentation, and either a VPN tunnel or temporary public URL to the test environment, depending on your preference.

Please include in your delivery:
• An executive summary that’s readable for non-technical leadership.
• A detailed technical report for developers, mapping each issue to the OWASP Top 10, complete with proof-of-concept steps, screenshots, and raw request/response data.
• CVSS-based risk ratings and clear remediation guidance.
• One complimentary retest to verify fixes.

Automated scanners (Burp Suite Pro, OWASP ZAP, sqlmap, etc.) are fine.