Research Library / Case Studies /

Fintech / Digital Payments

Secure Code Review for One of the Largest Online Payments Service Providers

A multi-million-dollar digital payments application asked Payatu to put its entire codebase under the microscope before attackers could. Our Bandits reviewed 18 modules manually and with automated in- house tools against OWASP secure coding principles, surfacing high-severity issues including a Log4Shell- vulnerable component.
Secure Code Review

At a glance

INDUSTRY

Fintech / Digital Payments

CLIENT PROFILE

Multi-million-dollar digital payments application

SERVICES

Secure Code Review

ENGAGEMENT

Manual and automated source code review of 18 modules

key Numbers

18

Modules Reviewed

24

Vulnerabilities Identified

Key Takeaways

  • Client – A multi-million-dollar payments application processing digital transactions at scale.

  • Problem – With 18 different modules in its codebase, the client needed assurance that its source code met OWASP secure coding standards before vulnerabilities could be exploited in production.

  • What Payatu did – We conducted a manual and automated secure code review of all 18 modules against OWASP secure coding principles and Payatu's custom checklist, covering injection, broken authentication, XXE, SSRF, insecure deserialization and other vulnerability classes.

  • Outcome – The review surfaced 7 high-severity and 17 medium-severity findings, including a Log4Shell-vulnerable component and multiple injection flaws, each paired with concrete remediation steps.

the challenge

Why the client called us in

Payments applications live and die by user trust, and that trust rests on secure code. The client's platform spans 18 distinct modules handling financial transactions, so any vulnerability buried in the codebase carried outsized risk. Rather than wait for an incident, the client approached Payatu to have its entire codebase reviewed manually and with in-house automated tooling against OWASP secure coding principles.

  • Identify vulnerabilities across all 18 modules before release
  • Validate compliance with OWASP secure coding principles
  • Get clear, actionable remediation guidance for every finding

scope of engagement

What was in scope

  1. 18 source code modules reviewed
  2. Manual & automated security assessment
  3. Advanced in-house security tools
  4. OWASP secure coding principles
  5. Payatu's custom security checklist

Our Approach

How Payatu ran the engagement

01

Information Gathering
We systematically collected data on the client's codebase, structure, dependencies and potential security risks.

02

Understanding the Application and its Components
We mapped the directory structure, modular components and interdependencies to review the code more thoroughly.

03

Establishing a Review Environment
An isolated, secure environment was created to conduct the review without exposing sensitive information.

04

Code Analysis
We manually reviewed the code for security vulnerabilities, coding standard violations and weaknesses, including injection, broken authentication and SSRF.

05

Reporting and Documentation
Every finding was documented with an explanation and mitigation strategy so the client could prioritize fixes.

Key findings

What we found

HIGH
Log4Shell and Other Vulnerable Components
The application was vulnerable to Log4Shell and other CVEs tied to outdated, vulnerable components.
HIGH
Expression Language Injection
Several endpoints allowed possible expression language injection.
HIGH
Path Traversal to File Disclosure
A path traversal flaw allowed disclosure of files outside the intended directory.
HIGH
Missing Authentication and Admin Code Injection
Authentication was not configured for some controllers, and admin functions were exposed to code injection via the system, tilde and exec functions.

the outcome

Results and Impact

The review gave the client a full picture of its security posture across all 18 modules, with 7 high and 17 medium-severity findings mapped directly to OWASP vulnerability categories. Each finding came with a specific remediation step, from upgrading vulnerable packages to masking sensitive data server-side, giving the engineering team a prioritized path to closing the gaps before they reached production.

‍

  • 18 modules reviewed manually and with automated tooling

  • 7 high-severity and 17 medium-severity findings identified and documented

  • Log4Shell exposure and injection flaws flagged for immediate remediation

  • Sensitive data such as VPA and bank account numbers flagged for server-side masking

  • Remediation guidance delivered for all 18 identified issues

Dark background with a flowing, curved red wave pattern across the center.

Get the full case study

Download the complete PDF - full methodology, findings and remediation detail.

Download Case Study (PDF)
White arrow pointing downward on a dark background.White arrow pointing downward on a dark background.

More Case Studies

No items found.
OT/ICS

Building a Security Program from Ground Up for a Security-Critical Government Agency in Asia

Read Case Study
No items found.
OT/ICS
No items found.
IoT & hardware

Payatu IoT Security Assessment Success Stories

Read Case Study
No items found.
IoT & hardware
Fintech
Infrastructure Security Assessment

National Bank Infrastructure Security Assessment

Read Case Study
Fintech
Infrastructure Security Assessment
Physical Security Assessment
Social Engineering Assessment
Security Awareness Training
Regulatory Compliance Assessment