VAPT for a Payment Gateway: Uncovering 12 Critical Vulnerabilities

A Tier-2 payment gateway processing ₹2,400 crore/month engaged eNeoteric for a combined web application and API penetration test. The engagement uncovered 12 critical vulnerabilities — including an IDOR flaw enabling cross-account fund access — and guided full remediation before a scheduled PCI-DSS audit.

12
Critical vulnerabilities
₹2,400 Cr
Monthly payment volume
60 days
Remediation window
0
Non-conformities at PCI-DSS audit

The Challenge

The client — a fast-growing payment aggregator authorised by RBI — was approaching their annual PCI-DSS re-certification and had internal concerns about the security posture of their newly launched merchant onboarding API. Their internal VAPT from the previous year had missed several critical findings, and the board had mandated an independent, manual penetration test before the audit window opened.

Key constraints: the test had to be conducted in a staging environment that mirrored production, all testing had to be non-disruptive to 24×7 payment processing, and the final report had to be in a format accepted by their QSA.

Our Approach

eNeoteric conducted a 10-day black-box / grey-box hybrid engagement covering:

  • Web application testing (OWASP Top 10 + OWASP ASVS L2)
  • REST API penetration testing (all 47 documented endpoints)
  • Authentication and session management deep-dive
  • Business logic testing — transaction flow, refund logic, settlement API
  • Mobile SDK testing (Android + iOS merchant apps)
  • Infrastructure review of the exposed perimeter (3 subnets)

Testing was performed by OSCP-certified engineers, with findings triaged daily in a shared Slack channel with the client's CTO and CISO.

Key Findings

The engagement produced 12 critical, 8 high, 14 medium, and 19 low / informational findings. The most significant:

  • IDOR in refund API — Merchants could modify merchant_id in refund requests to trigger refunds to arbitrary bank accounts. Exploitable without authentication bypass; estimated potential loss ₹50L per exploit chain.
  • JWT algorithm confusionRS256HS256 downgrade attack gave unauthenticated access to admin console.
  • SQL injection in report export — Time-based blind SQLi in the transaction export endpoint; full database read possible.
  • Exposed Swagger UI in production — Internal API documentation publicly accessible, reducing attacker reconnaissance time significantly.
  • Weak TLS configuration — TLS 1.0 still negotiable; CBC cipher suites accepted on payment endpoints.

Outcomes & Impact

eNeoteric provided developer-specific remediation guidance for every finding. A complimentary re-test 45 days post-engagement confirmed 100% closure of all Critical and High findings. The client subsequently passed their PCI-DSS Level 1 re-certification audit with zero security non-conformities related to the tested scope.

The CTO later used the IDOR finding as a case study in their internal developer security training, reaching 40+ engineers.

“The IDOR in our refund API was a critical miss from our previous vendor. eNeoteric's manual testing found what automated scanners couldn't — and the remediation guidance was specific enough that our developers could action it immediately.”
CISOLeading Indian Payment Aggregator

Related services

← All Case Studies Discuss your use case →

Request a Callback

Drop your details and we'll call you back within one business day — or reach us directly on +91 91080 15170.

💬 Chat on WhatsApp instead
Chat on WhatsApp