Harden Social Media Web App

via Freelancer ·

Budget / Salary$10–30
TypeFreelance project
LocationRemote
Posted1 hour ago
I need a seasoned vulnerability researcher to comb through my social-media-style web application and surface every exploitable path to Cross-Site Scripting (XSS) or Cross-Site Request Forgery (CSRF). The codebase is a typical React front-end served by a Node/Express API with a MongoDB backend, all containerised in Docker and running behind Nginx.

Scope
The engagement covers the full production replica: unauthenticated, authenticated, and privilege-escalation flows, including upload modules, messaging, profile edits, and any third-party integrations. Only web vectors are in scope; mobile clients and network infrastructure scanning are out of scope for now.

Methodology
Feel free to bring your own toolkit—Burp Suite Pro, OWASP ZAP, custom scripts, browser dev-tools extensions—so long as findings are reproducible. I will supply you with test accounts, API keys, source maps, and a staging URL.

Deliverables
• A concise report for each verified XSS or CSRF issue, detailing:
 – Step-by-step reproduction (with screenshots or PoC scripts)
 – Impact assessment (data theft, account takeover, etc.)
 – Recommended remediation or patch code snippet
• A final executive summary ranking all issues by criticality (OWASP severity scale).
• Optional follow-up retest once fixes are deployed (counted as a separate milestone).

Acceptance Criteria
A deliverable is accepted when the provided PoC reliably triggers on the current staging build, the write-up is clear enough for my devs to reproduce, and the remediation advice is technically sound.

Timeline
Initial findings expected within one week of access; complete report within two.

If this fits your skillset, let’s get you into the environment and start breaking things—before the bad actors do.
linux nosql couch & mongo nginx node.js penetration testing docker mongodb api testing
Apply on Freelancer →

Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.