Throughout the course so far you have found and exploited weaknesses. A professional's job does not end there. The deliverable that actually gets a vulnerability fixed is the report.
An exploit no one can reproduce, prioritize, or understand is worthless to the developers who must fix it. A good report turns a clever moment into a repeatable engineering task: a clear owner, a justified priority, and a concrete fix.
In this professional-practice lesson you will:
- Learn the anatomy of a vulnerability report — title, severity, location, reproduction, impact, remediation, evidence.
- Express severity with a CVSS base vector that anyone can reproduce, and write one yourself.
- See why technical severity (CVSS) and business impact are not the same thing.
- Understand coordinated disclosure, the 90-day norm, safe harbor, and CVE assignment.
Estimated time: 10 to 15 minutes. This is a reflective lesson; there is no offensive payload to run against the application — you will be writing about a finding from an earlier lesson.
When you are ready, send the Continue signal.