Research Library / Case Studies /

HR Technology (SaaS)

Web, Mobile and Cloud Security Assessment of a Thriving HR Product

A fast-growing HR product needed its web app, Android and iOS apps, and AWS cloud environment assessed before launch, on a tight compliance timeline. Payatu found a pre-authentication account takeover in the web app plus dozens of cloud misconfigurations, and worked with the client through fix and revalidation.
Web Security Assessment, Mobile Security Assessment (Android & iOS), Cloud Configuration Review

At a glance

INDUSTRY

HR Technology (SaaS)

CLIENT PROFILE

A fast-growing HR product used by employers, recruiters, and applicants

SERVICES

Web Security Assessment, Mobile Security Assessment (Android & iOS), Cloud Configuration Review

ENGAGEMENT

Pre-launch, multi-track security assessment

key Numbers

64

Vulnerabilities Identified Across Web, Mobile & Cloud

41

Cloud Misconfigurations Found in AWS

Key Takeaways

  • Client – A fast-growing HR product changing how employers, recruiters, and applicants manage hiring.

  • Problem – The product needed its web app, Android and iOS apps, and AWS cloud environment assessed before launch, against tight compliance and security timelines.

  • What Payatu did – Payatu Bandits ran a web security assessment, Android and iOS mobile assessments against the OWASP Mobile Top 10, and a cloud configuration review across 17+ AWS service categories.

  • Outcome – The team found 64 issues in total, including a critical pre- authentication account takeover that was fixed, and worked with the client through remediation and revalidation.

the challenge

Why the client called us in

The client's HR product was gaining real traction, changing how employers,
recruiters, and applicants handle hiring, and was about to expand its influence
further. Before launch, the company needed to be sure its web application,
mobile apps, and AWS cloud environment could hold up to real-world attackers,
while also meeting its compliance and security timelines. It brought in Payatu to
assess its full ecosystem, web, mobile, and cloud, in one coordinated
engagement.

  • Assess the web application, Android app, and iOS app for exploitable vulnerabilities
  • Review the AWS cloud environment for misconfigurations and excessive permissions
  • Get a prioritized, business-impact-driven remediation plan before launch

‍

scope of engagement

What was in scope

  1. Web Security Assessment
  2. Mobile Security Assessment (Android and iOS)
  3. Cloud Configuration Review

Our Approach

How Payatu ran the engagement

01

Web application assessment
Payatu used Burp Suite along with automation tooling to test access control, authentication and authorization, error handling, and input validation across the web application, uncovering 12 findings including a critical pre-authentication account takeover.

02

iOS mobile application assessment
The team assessed the iOS app against Payatu standards and OWASP testing guidelines from a jailbroken device, finding 8 issues including cached screenshots, unencrypted CSRF and device tokens, and an unencrypted local database file.

03

Android mobile application assessment
Over a three-day assessment following the OWASP Mobile Top 10 (2016), Payatu used Burp Suite, MobSF, Objection, Frida, Drozer, and other tools on a rooted device or emulator, identifying 3 issues including missing SSL pinning and partial code obfuscation.

04

Cloud configuration review
Following Payatu's Cloud Security Methodology v2.0, the team used AWS CLI, Scout Suite, Pacu, and in-house tools to review IAM, RDS, S3, EC2, and over a dozen other AWS services, identifying 41 misconfigurations.

05

Revalidation and reporting
Payatu revalidated fixes with the client's team, marking issues as Fixed or Not Applicable based on retesting or client feedback, and delivered a report customized to the client's preferences.

Key findings

What we found

CRITICAL
Pre-Auth Account Takeover
An attacker could take over a user's account by manipulating the invitation flow before it was created, without any verification tied to the victim's email. This was fixed by the client.
HIGH
Privilege Escalation in the Settings Module
A flaw in the settings module allowed users to escalate their privileges within the application.
HIGH
Misconfigured IAM Roles
Payatu found IAM roles misconfigured across the AWS environment, creating a path to privilege escalation, alongside unused credentials older than 90 days.
HIGH
Unencrypted Storage Across AWS Services
RDS instance storage, EBS volumes, and multiple other AWS resources were left unencrypted, exposing data to attackers who gained access to the underlying infrastructure.

the outcome

Results and Impact

Across web, mobile, and cloud, Payatu identified 58 issues, ranging from a critical account takeover to dozens of cloud misconfigurations, and worked with the client's team through fix verification before launch. The client resolved its highest-risk findings and made informed, business-
driven calls on the rest.

‍

  • Found and helped fix a critical pre-authentication account takeover

  • Assessed web, Android, iOS, and AWS cloud in one coordinated engagement

  • Identified 41 cloud misconfigurations across IAM, RDS, S3, EC2, and more

  • Delivered a report customized to the client's preferences under a tight timeline

Dark background with a flowing, curved red wave pattern across the center.

Get the full case study

Download the complete PDF - full methodology, findings and remediation detail.

Download Case Study (PDF)
White arrow pointing downward on a dark background.White arrow pointing downward on a dark background.

More Case Studies

No items found.
OT/ICS

Building a Security Program from Ground Up for a Security-Critical Government Agency in Asia

Read Case Study
No items found.
OT/ICS
No items found.
IoT & hardware

Payatu IoT Security Assessment Success Stories

Read Case Study
No items found.
IoT & hardware
Fintech
Infrastructure Security Assessment

National Bank Infrastructure Security Assessment

Read Case Study
Fintech
Infrastructure Security Assessment
Physical Security Assessment
Social Engineering Assessment
Security Awareness Training
Regulatory Compliance Assessment