sample report · fictitious data

What you get

Every engagement ends in a signed, dated report like this one. Here is the shape, with made-up findings — including the loop that is the point: a critical found, fixed, and retested to closed.

rheono

Security Snapshot

Continuous, human-verified security testing (Standing Hunt) · stand: 09.09.2026

Scope

In scope: acme.example (root domain) — www.acme.example, api.acme.example, 42 endpoints (web + REST API). Techniques: external, non-mutating; auth tests with provided test accounts; no port scanning, no DoS. Test window: 01.08.2026 – 09.09.2026. Out of scope: internal networks, mobile apps, social engineering.

Executive summary

Executive summary: in scope (acme.example), 2 findings were documented between 01.08 and 09.09.2026 — 1 critical (IDOR) and 1 high (SQL injection). The critical IDOR was fixed in one release and retested on 26.08.2026, verified closed. The high SQL injection remains open. Every finding is human-verified, mapped to ISO 27001 / NIS2, CVSS-scored, and carries a recommended fix.

Findings (2)

[CRITICAL]closed · retested

IDOR: sequential order IDs expose other customers' full order history

CVSS 9.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) · CWE: CWE-639

ISO/IEC 27001:2022: A.8.29, A.5.15 · NIS2: Nr. 7

First found: 24.08.2026

Fixed 25.08.2026 (release 2026.08.2) · retested 26.08.2026 — verified closed

PoC: idor-order-history

Remediation: Enforce object-level authorization: resolve the owner server-side from the authenticated session and reject requests where the resource owner does not match; add regression test coverage.

[HIGH]open · first detection

SQL injection in /api/login

CVSS 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) · CWE: CWE-89

ISO/IEC 27001:2022: A.8.29, A.8.28 · NIS2: Nr. 5+6

First found: 01.09.2026

PoC: sqli-login

Remediation: Use parameterized queries in the login route (no string concatenation), whitelist the sort fields, then re-test with the PoC.

Retest

IDOR (critical) retested 26.08.2026 — fix confirmed, finding closed. SQL injection (high) open — next retest after the fix, by 15.09.2026 at the latest.

Attestation

Attestation: Rheono, named researcher Samir Abis, tested the scope above externally and non-mutatingly. Every finding was verified manually by proof of concept. This snapshot is a documented state at the stand date: no guarantee of the completeness of all weaknesses and no guarantee of regulatory compliance.

Status

Next snapshot: by 08.12.2026 or right after the next release.

Signature

Samir Abis · named researcher, rheono

Advanced electronic signature (eIDAS, PAdES-B-T) + qualified timestamp (RFC 3161)

More about the processTrust & security