Web App Vulnerability Assessment

Job ID: 40502989

Budget: €30 – €250 EUR

I need a seasoned ethical hacker to probe my public-facing web applications and surface every weakness before attackers do. The core goal is to identify vulnerabilities; no remediation work is required at this stage, but I do want clear, reproducible evidence for each flaw.

Scope
The assessment must cover the full web stack—front-end, back-end, APIs and any server-side components tied to the apps. Automated scanning is fine as a first pass, yet I expect you to validate every finding manually and look beyond scanner results for business-logic or access-control issues.

High-priority findings
Please focus your efforts on:
• SQL injection
• Cross-site scripting (XSS)
• Cross-site request forgery (CSRF)

You are free to uncover and report additional issue types, but the three above are non-negotiable.

Methodology & tools
Follow OWASP Testing Guide principles. Tools such as Burp Suite, OWASP ZAP, sqlmap or custom scripts are welcome as long as they are used responsibly and within the agreed test window.

Deliverables
1. A concise executive summary outlining overall risk.
2. A technical report for each vulnerability containing: steps to reproduce, affected endpoints, impact analysis and mitigation advice.
3. Proof-of-concept payloads or screenshots for critical findings.
4. A retest checklist so I can verify fixes later.

Acceptance criteria
• All three vulnerability categories are thoroughly checked.
• False positives are removed; every issue is reproducible.
• Reports are delivered in both PDF and editable format.
• No disruption to live services during testing.

Let me know your estimated timeline, required test access and any legal paperwork you need signed, and we can get started.