assessment_01
Firebase-backed Next.js SaaS platform
- Recon against the public site and its client-side JavaScript bundles.
- Found a credential hardcoded in a public-facing debug page, which gave authenticated access as a staff/admin account (no MFA in place).
- Identified broken access control on an administrative API that allowed unauthorized privileged actions.
- Reported with reproduction steps, business impact and a prioritized fix list: rotate credentials, enforce MFA, add server-side authorization checks.