
Years in Business
WeRentt is a PropTech platform focused on simplifying property rental and real estate transactions. The platform supports property discovery and rental-related digital workflows while its broader ecosystem includes tenant and owner applications together with CRM capabilities.
For this engagement, Nextwebi focused on assessing the security posture of the customer-facing web application and identifying potential vulnerabilities across critical application functions.
WeRentt operates a feature-rich property platform where users can search for homes and interact with property-related services. The platform supports property listings, tenant and owner workflows and connected application functionality. Since these workflows can involve user accounts, property information, personal documentation and transaction-related data, application security is an important consideration.
The assessment was structured to discover vulnerabilities across the exposed application surface while validating authentication, authorization, session security, input handling, APIs and business logic. The engagement also focused on practical remediation guidance for the development team.
Login functionality, OTP authentication, authentication bypass scenarios, account enumeration and brute-force protection.
Horizontal and vertical privilege escalation, unauthorized resource access, object-level authorization and role-based controls.
Session tokens, expiry, invalidation, cookie security, fixation and logout behaviour.
SQL Injection, Cross-Site Scripting, HTML injection, parameter tampering and malicious input handling.
Property search, property details, enquiry, booking and rental-related workflow manipulation.
Endpoint discovery, authentication, authorization, parameter handling, excessive data exposure and error handling.
Potential disclosure through API responses, errors, source code, browser storage and public resources.
HTTP security headers, CORS, SSL/TLS, cookie attributes, cache controls and server information disclosure.
Testing covered login mechanisms, OTP-based authentication, authentication bypass, account enumeration, brute-force protection and authentication response handling.
Testing covered horizontal and vertical privilege escalation, direct URL access, object-level authorization, role-based controls and parameter manipulation.
Nextwebi assessed session token handling, expiry, invalidation, cookie security, session fixation, logout behaviour and concurrent session handling.
Application inputs were assessed against SQL Injection, Cross-Site Scripting, HTML Injection, Command Injection, parameter tampering and malicious input handling.
Property search, property details, enquiry, booking and rental-related workflows were assessed for unauthorized progression, parameter manipulation and workflow bypass.
Backend APIs were assessed for endpoint exposure, authentication, authorization, object-level access issues, excessive data exposure, error handling and rate-limiting controls.
Application responses, error messages, source code, browser storage, parameters and public resources were reviewed for unnecessary sensitive information disclosure.
HTTP security headers, CORS, cookie attributes, SSL/TLS configuration, cache controls and technical information disclosure were reviewed.
Nextwebi followed a structured security testing lifecycle that combined automated assessment with manual validation. The engagement used Black Box and Grey Box perspectives so the application could be assessed from an external attacker viewpoint and through controlled testing of application functionality.
Map application surface, technologies, endpoints and accessible functionality.
Identify entry points, user flows, APIs and exposed resources.
Identify potential weaknesses using automated tools and targeted analysis.
Verify findings and assess behaviour that automated scanners may not detect.
Validate practical security impact through controlled testing.
Classify validated findings using severity, exploitability and business impact.
Document findings and validate remediation after fixes where included in the engagement.
Testing authentication and authorization controls helps identify weaknesses that could lead to unauthorized account access.
Access control testing helps validate that users can access only information intended for their role.
Testing property and rental workflows helps identify business logic weaknesses that could affect operations.
API testing provides visibility into vulnerabilities that may affect web and connected mobile applications.
Security findings and recommendations provide clear areas for strengthening the application.
Nextwebi's Web Application Security Testing for WeRentt was structured around the security requirements of a modern PropTech platform. The assessment covered authentication, authorization, session management, application inputs, APIs, business logic and security configurations.
The engagement provided a structured framework for identifying potential security weaknesses across the customer-facing application while supporting stronger protection of user accounts, property information and application workflows.
The approach also provides a foundation for integrating security testing into the application development lifecycle as the WeRentt digital ecosystem continues to evolve.
Let's talk about how we can craft a user experience that not only
looks great but drives real growth for your product.!