Web Application Security Testing
Challenge
The client requested a security assessment of their web application while exploring the use of AI. They were experimenting with three different language processing techniques, including OpenAI’s large language models, which increased potential security risks.
Solution
The ivision team conducted a web application penetration test and identified exploitable SQL injection vulnerabilities across all three language processing techniques. They also discovered that the OpenAI-based language processing was susceptible to prompt injection. Overall, the client’s web application was vulnerable to SQL injection attacks that could allow an attacker to access arbitrary database information.