Qualysec

Strengthening Web Application Security for a US-Based E-Commerce Merchandise Platform

Qualysec helped a US-based e-commerce merchandise platform strengthen the security of its web applications by identifying critical vulnerabilities, validating every finding manually, and establishing a recurring security program through quarterly vulnerability assessments.

United States

E-Commerce Merchandise Platform

2

Web Application

80 Employees

Corporate Merchandise Solutions

Quarterly VA Scans

Recurring Security Assessment

Who is the client

A US-Based E-Commerce Merchandise Platform

A US-based e-commerce company with a team of 80 employees. The company provides branded promotional products, corporate apparel, and custom company store solutions, helping organizations manage brand visibility and merchandise programs.
Corporate Merchandise80 EmployeesCustom Company StoresBrand Management Solutions

What Was Tested

The engagement covered two web applications, along with a quarterly vulnerability assessment (VA) scan. The client wanted to ensure both applications were operating securely while using recurring VA scans as an additional security layer between full penetration testing engagements.

Web Application

Web Application
Reasons for choosing Qualysec

4 Reasons They Trusted Qualysec Over Others

Supporting business-critical web applications requires more than a one-time penetration test. The client needed a long-term security partner capable of providing recurring assessments, manual penetration testing, and remediation support without disrupting day-to-day business operations.

Finds what automation misses

Broad Cybersecurity Services

Qualysec supported both comprehensive penetration testing and recurring quarterly vulnerability assessment scans under a single engagement, eliminating the need to coordinate multiple vendors.

Compliance-Oriented Reporting

Human-Led Testing

The client wanted manual security testing capable of identifying business logic flaws and application-specific vulnerabilities across two separate web applications, rather than relying solely on automated scanning.

Competitive Pricing

Competitive Pricing

Qualysec's pricing structure aligned with the client's requirement to secure multiple applications while maintaining an ongoing quarterly scanning program within budget.

Retesting Process

Retesting Process

Knowing that every implemented fix would be verified through structured retesting gave the client confidence that vulnerabilities would be fully remediated instead of simply documented.

REFERRED BY A SECURITY-FIRST APPROACH

By combining human-led penetration testing, recurring quarterly vulnerability assessments, collaborative remediation support, and structured retesting, Qualysec delivered a long-term security program rather than a one-time assessment.

★★★★★

Peer-verified

Trusted worldwide

Top Findings

Top 5 Significant Findings

Insecure Direct Object References (IDOR) on Order Invoices

Critical

The checkout API failed to validate user session ownership against order IDs, allowing authenticated users to view corporate purchase orders, delivery addresses, and transaction histories belonging to other companies.

Potential impact: Unauthorized access to sensitive corporate order information.

Mass Assignment on User Profile Endpoint

High

The profile update functionality allowed hidden parameters to be modified, enabling attackers to elevate user roles or grant unauthorized corporate merchandise discounts.

Potential impact: Privilege escalation and unauthorized account modifications.

Stored Cross-Site Scripting (XSS) in Custom Merchandise Input

High

Custom branding text submitted through merchandise order forms was not properly sanitized, allowing malicious scripts to execute whenever administrators or store managers reviewed pending orders.

Potential impact: Administrator account compromise and malicious script execution.

Broken Object Level Authorization in Cart Management

Medium

The cart management API allowed manipulation of pricing parameters and product quantities, enabling unauthorized modification of product pricing during the corporate checkout process.

Potential impact: Financial manipulation and unauthorized pricing changes.

Cross-Site Request Forgery (CSRF) on Shipping Address Updates

Medium

State-changing forms lacked unique anti-CSRF protection, allowing attackers to trick authenticated users into unknowingly changing default shipping addresses to unauthorized destinations.

Potential impact: Unauthorized account changes and fraudulent shipment redirection.

What Could Have Happened Without This Assessment

If these vulnerabilities had remained unresolved, attackers could have exploited weaknesses across both applications to gain unauthorized access to corporate purchasing information, manipulate pricing, compromise administrator accounts, and interfere with critical business operations.

The Result & Remediation

Not Just a Report - A Stronger Security Baseline

Qualysec didn't simply identify vulnerabilities. All 20 security findings across both applications were documented, validated, and supported with a practical remediation roadmap. The engagement helped the client establish a measurable security baseline supported by recurring quarterly vulnerability assessments

The Remediation Process

01

Vulnerability Validation

Every identified vulnerability across both web applications was manually verified to confirm exploitability and eliminate false positives before remediation began.

02

Developer Collaboration

Qualysec worked directly with the client's engineering team to review every finding, explain the associated risks, and implement fixes without interrupting the daily operation of either platform.

03

Ongoing Monitoring

Quarterly vulnerability assessment scans became part of the client's long-term security strategy, allowing future scan results to validate remediation efforts and continuously monitor the security posture of both applications.

The Results Achieved

Long-Term Security Roadmap

Continuous assessment strategy established for future growth.

2 Web Applications

Security Strengthened

Quarterly VA Scans

Ongoing Security Monitoring Established

Platform

Security Baseline

Established for Continuous Improvement

GET A QUOTE

Ready to Stay Ahead of Attackers?

If You need a Penetration test, Let’s have a Talk. Fill out this form and we will ensure you are secured and hit full compliance without any hurdles. The immediate impact you can expect:

  • Our sales team will reach out instantly

  • We skip the back-and-forth to meet your deadline perfectly

  • We get your testing scheduled immediately without any delay

Total No. Of Vulnerabilities

0+

Total No. Of Vulnerabilities

Years in Business

0+

Years in Business

Assessment Completed

0+

Assessment Completed

Trusted Clients

0+

Trusted Clients

Countries Served

0+

Countries Served