CASE STUDY · AGRITECH AND AGRICULTURAL MARKETPLACE

One shared API key exposed every farmer’s data

A web application and API penetration test for an agricultural marketplace platform, covering the farmer-facing web platform and every backend API behind it.

Get Scoped See CredShields One
/ Engagement

The scope, in short

ENGAGEMENT TYPE
Web application and API penetration test
SCOPE
Farmer-facing web platform and all backend APIs
INDUSTRY
AgriTech, agricultural marketplace
/ Findings overview

Nineteen findings, one critical

19
TOTAL FINDINGS
1
CRITICAL
5
HIGH
3 + 9 + 1
MEDIUM + LOW + INFO
/ Key risk areas identified

What the engagement found

01

System-wide broken access control via a shared API key: a single compromised credential exposed all platform data.

02

Password hashes exposed in plain text in API responses, letting an attacker crack and hijack any farmer account.

03

OTP verification bypass via client-side response manipulation, fully circumventing phone and email identity verification.

04

IDOR in user profiles: any authenticated user could view any other farmer’s personal identity and contact details.

05

No rate limiting on the login endpoint, leaving accounts vulnerable to brute force and credential stuffing.

06

A farmer-specific API endpoint accessible with no authentication, making all farmer data readable by anonymous users.

07

SMS and email OTP flooding: unlimited OTPs triggerable by any user, enabling spam abuse and cost escalation.

/ Outcome

A complete security overhaul of the farmer-facing platform: the strongest full-remediation outcome across CredShields’ web application engagement history.

/ Relevant for

If this looks like your environment, it probably behaves like it too

Marketplace platforms with user registration and OTP-based identity flows.

AgriTech and rural-facing digital platforms.

Any B2C or B2B2C platform where user data isolation and identity verification integrity are critical.

/ FAQ

Questions engagements like this raise

How dangerous is a shared API key in practice?

As dangerous as the single most exposed place it is used. One shared secret means one leak, one scraped mobile app, or one careless log line compromises every customer’s data at once, not just one account.

Why does OTP bypass matter if passwords are also required?

Because platforms usually treat OTP verification as the trust anchor for identity, not just a password backstop. Bypassing it lets an attacker claim to be a verified farmer without ever proving phone or email ownership.

Why store password hashes at all if they should never be exposed?

Hashing protects passwords at rest, assuming the hash never leaves the database. Returning it in an API response defeats that protection entirely, regardless of how strong the hashing algorithm is.

What made the remediation outcome the strongest on record?

Every finding, including the critical shared-key issue, was fixed and confirmed on retest with no items left as accepted risk, which is not the case in every engagement.

/ More case studies

Other engagements

Web + API

Capx AI token launch platform

7 findings led by a critical SSRF in the API proxy.

Read →
Exchange

Indian crypto exchange

High-volume transaction systems under test.

Read →
SaaS

APAC coworking SaaS

Booking and subscription flows the business runs on.

Read →
/ Get started

Start with a scoped assessment

Tell us what you are securing. We reply with scope and next steps within one business day.

Scoping within a day, findings within the first week A senior pentester on every engagement Scope and pricing before you commit

Prefer to see it first? Book a demo ↗

Already a CredShields One customer? Log in ↗

Request received We respond within one business day. For urgent requests, email [email protected].
We respond within one business day.
OR
Book a demo ↗