Web App XSS Penetration Test
Budget / SalaryA$1,500–3,000
TypeFreelance project
LocationRemote
Posted1 hour ago
I need an experienced penetration tester to focus exclusively on our React-based web application and uncover every possible Cross-Site Scripting (XSS) weakness and any network weakness. You will receive access to a staging instance, user roles, and any documentation you need so you can test thoroughly without disrupting production.
Your task is to emulate a real attacker: map the full attack surface, attempt both reflected and stored XSS, and verify any bypasses of our current content-security policies. Please keep notes as you go; a concise, well-structured report is the final deliverable.
Additionally, the scope includes authenticated, unauthenticated, and mobile app tests. Testing will occur closer to November after development and infrastructure updates are complete. The budget for this project is 2,000 AUD.
Deliverables:
• Step-by-step description of each XSS finding with proof-of-concept payloads and impact assessment
• Clear reproduction steps we can hand to developers
• Practical remediation advice that aligns with modern React best practices
• A short re-test summary once fixes are in place
If you already have a proven toolkit for React applications—Burp Suite, OWASP ZAP, custom scripts—feel free to use it. I’m aiming for actionable insight rather than a generic scan, so manual verification is essential.
Your task is to emulate a real attacker: map the full attack surface, attempt both reflected and stored XSS, and verify any bypasses of our current content-security policies. Please keep notes as you go; a concise, well-structured report is the final deliverable.
Additionally, the scope includes authenticated, unauthenticated, and mobile app tests. Testing will occur closer to November after development and infrastructure updates are complete. The budget for this project is 2,000 AUD.
Deliverables:
• Step-by-step description of each XSS finding with proof-of-concept payloads and impact assessment
• Clear reproduction steps we can hand to developers
• Practical remediation advice that aligns with modern React best practices
• A short re-test summary once fixes are in place
If you already have a proven toolkit for React applications—Burp Suite, OWASP ZAP, custom scripts—feel free to use it. I’m aiming for actionable insight rather than a generic scan, so manual verification is essential.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.