VulnBank Penetration Testing Walkthrough: Findings, Impact and Fixes
I completed a full penetration test of VulnBank, an intentionally vulnerable online-banking application built for security training. The walkthrough follows the assessment from reconnaissance and testing through exploitation, business impact and remediation. The findings cover weak JWT handling, broken object-level and property-level authorisation, SQL injection, XSS, race conditions, mass assignment, GraphQL misconfigurations, SSRF, insecure file uploads, information disclosure, session weaknesses, and flaws affecting virtual cards and bill payments. The full write-up includes HTTP requests and responses, relevant test payloads, screenshots, impact analysis and practical fixes. It is designed for cybersecurity professionals, developers and students who want to understand how modern web applications are assessed ethically. I welcome feedback and discussion from anyone learning penetration testing or application security.
Stories are shared by community members. This article does not represent the official view of NaijaWorld — the author is solely responsible for its content.

