All cheatsheets

Cheatsheet · beginner

Finding / report template

Copy-ready structure for professional vulnerability write-ups.

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

reporting
writing

Markdown finding

Command
## [SEVERITY] Short descriptive title

**Asset:** host / app / URL  
**Category:** e.g. Broken Access Control / Injection  
**Status:** Open

### Description
What is wrong in plain language (1–3 sentences).

### Business impact
Who is affected, what an attacker can do, realistic harm.

### Technical details
Root cause, affected parameter/endpoint, auth context.

### Steps to reproduce
1. …
2. …
3. …

### Evidence
- Request/response (redact secrets)
- Screenshot references
- Tool output filenames

### Remediation
Specific fix (code/config/process). Prefer primary control + defense in depth.

### References
OWASP / CVE / vendor advisory (if any)

Severity quick rubric

Command
Critical: full compromise / mass sensitive data
High: significant data or priv abuse
Medium: limited impact or harder exploit
Low: defense-in-depth / info leak minor
Info: no direct exploit path

Checklist

  • Impact stated in business language
  • Repro works from steps alone
  • Evidence attached and redacted
  • Remediation is actionable, not 'be secure'