The Endpoint Wasn't Vulnerable. The Attack Chain Was.
Introduction The first finding wasn't critical. It wasn't even particularly interesting. There was no SQL Injection. No Remote Code Execution. No authentication bypass. Just an API endpoint that shouldn't have been exposed. On its own, it looked like a low-severity finding. But penetration testing isn't about collecting vulnerabilities. It's about understanding what those vulnerabilities can…
We haven't written up this one. Dev.to has the full story — the link below goes straight to it.