Web Security Penetration Test Report XPE-01

CyberJutsu Final Exam - XimiPlace Pentest Report

Final exam penetration testing report for CyberJutsu Academy, covering the XimiPlace authorized lab application. The assessment documents access control issues, stored XSS, exposed internal files, SSRF, second-order SQL injection, insecure Java deserialization, and an exploit chain leading to remote code execution.

Published
Jun 20, 2026
Pages
82
Environment
CyberJutsu Lab - XimiPlace
Report ID
XPE-01
Tags
XimiPlace CyberJutsu Final Exam Web Pentest Security Lab Blackbox Testing OWASP

Assessment Overview

Objective
Document the CyberJutsu final exam black-box testing process, identified vulnerabilities, root causes, exploitation evidence, impact, and remediation guidance.
Scope
The assessment scope is limited to the XimiPlace lab application at ximiplace.exam.cyberjutsu-lab.tech.
Authorization notice
Testing was performed against the authorized XimiPlace lab environment for learning, security assessment practice, and application security reporting.

Key Topics

XimiPlace CyberJutsu Final Exam Web Pentest Security Lab Blackbox Testing OWASP Java Spring Data JPA React Docker Compose SQL

Tools Used

Burp Suite ffuf SecLists Webhook.site ngrok Python/Flask curl git Java JDK Browser Developer Tools

PDF Preview

Read Online

Open PDF Fullscreen

PDF preview unavailable

Your browser cannot display this PDF inline. Open the PDF in a new tab to view the report.

Open PDF