Penetration Tester, INI.GE Group Ltd.
Oct, 2025 - Nov, 20251 month
I conducted a comprehensive Black Box Vulnerability Assessment of the Angular-based student portal, focusing on identifying and reporting security flaws in a Server-Side Rendered (SSR) environment. My detailed technical reporting enabled the development team to swiftly cooperate and remediate critical issues.
Discovered and reported an Insecure Direct Object Reference (IDOR) vulnerability in the storage infrastructure, allowing unauthorized access to sensitive files and documents.
Identified Broken Access Control vulnerabilities that exposed internal user data and password hashes.
Detected hardcoded API secrets exposed within client-side JavaScript chunks.
Demonstrated Stored XSS vulnerabilities within rich-text input fields.