Offer

Free security assessment — you only subscribe if we find a P0 or P1 vulnerability.

Claim free assessment
CyVigilant
All case studies
Health, Beauty and Personal Care

How Avimee Herbal Closed 35 Security Gaps Across Three Critical Platforms with CyVigilant VAPT

Avimee Herbal's customer accounts, employee records, and financial data sat one API call away from full exposure. Across a structured VAPT of its three internet-facing platforms, CyVigilant identified 35 vulnerabilities, including 14 Critical and 8 High severity findings, and showed how an open database, a credential-leaking API, and mass IDOR across more than 10 million records could be chained into a full compromise. Every Critical and High finding was then remediated and retested to closure.

100%Critical and High findings fixed and retested
1 Critical8 High13 Medium13 Low
Web Application VAPT API SecurityERP Security Review
The Challenge

Avimee Herbal Private Limited is a consumer healthcare and direct-to-consumer wellness brand running three internet-facing platforms: a Shopify e-commerce storefront, an Odoo ERP system, and a healthcare consultation portal. These systems handled daily operations, customer transactions, and healthcare services. As the business scaled, security gaps across the applications went unnoticed, raising the risk of unauthorised access to sensitive customer, employee, and financial data. The team needed a real-world assessment of how exposed these platforms actually were, not another checkbox scan.

Our Approach

CyVigilant ran a structured Vulnerability Assessment and Penetration Testing engagement across all three platforms, using methodologies aligned with the OWASP Testing Guide v4.2, PTES, and NIST SP 800-115. The engagement moved through four stages:

Reconnaissance

Vulnerability assessment

Exploitation

Reporting

Rather than list issues in isolation, CyVigilant validated each finding and showed how weaknesses could be chained during a real-world attack, from unauthenticated database access to API-based credential exposure and large-scale IDOR. The engagement concluded on 20 December 2025 with a detailed remediation report (Version 6.0), prioritised by business impact and technical risk so the team could fix the highest-risk issues first.

Findings

Testing confirmed a set of high-impact exposures across the three platforms:

Unauthenticated database access. The Odoo database manager was publicly accessible and required no authentication, letting anyone who found the interface interact with the database directly.

Credentials leaking through an API. A single API endpoint returned sensitive user data, including password hashes, salts, and one-time passwords, when given a valid phone number, exposing authentication data and opening a path to account compromise.

Mass IDOR across 10 million plus records. Multiple Insecure Direct Object Reference flaws across 43 plus Odoo data models allowed unauthorised access to more than 10 million records with no access validation.

Missing security headers. Security headers were absent across multiple assets, weakening baseline protection on all three platforms.

Chained together, these weaknesses left customer, employee, and financial data one step from full exposure.

Outcome

Following remediation, Avimee Herbal closed every Critical and High severity finding from the engagement. The Odoo database manager was moved behind authentication, the credential-leaking API was eliminated, access controls were enforced across the previously IDOR-exposed Odoo data models, and security headers were implemented across all three platforms. Beyond the individual fixes, the engagement gave the team a clear, prioritised roadmap for ongoing security work.

The findings also carried regulatory weight under GDPR Article 32, India's Digital Personal Data Protection Act, 2023, and Section 43A of the Information Technology Act, 2000, making remediation a compliance priority as well as a security one.

"CyVigilant didn't just hand us a list of issues. They showed us exactly how an attacker would chain these vulnerabilities together. Seeing the Odoo database manager open to the internet and our healthcare API leaking credentials in the same report was the wake-up call our team needed to prioritise security at every layer."
— Chief Technology Officer, Avimee Herbal Private Limited

Results
35
Vulnerabilities identified
14
Critical findings, all remediated
10M+
Records secured against IDOR
100%
Critical and High retested to closure
Get started

Find what your scanners are missing.

Book a scoping call with an expert and get an exploit-led assessment of your own stack.

Talk to an Expert