en

Security Testing of the DonorUA Medical Platform

Client:
DonorUA – a nationwide initiative and IT platform for the development of blood donation.
Industry:
Healthcare
Focus:
Security testing of web applications, protection of personal and medical data
Main challenge:
Identifying vulnerabilities in web services that process personal and medical information
Market:
Ukraine
Services provided:
Key Takeaways
  • Provided a security recommendations report.
  • No critical security threats were confirmed.
  • A black-box pentest of two web applications was performed.
  • 13 vulnerabilities were identified: 2 medium, 9 low, and 2 informational.
  • A combination of automated and manual testing was applied.
  • 13
    vulnerabilities found
    2
    web applications tested
    2 weeks
    project duration
    Security Testing of the DonorUA Medical Platform
    Developing software according to security best practices is not yet a guarantee of full protection. DonorUA approached Datami to test their web applications. The automated pentest revealed a number of vulnerabilities, including a brute-force attack on the login page and vulnerable libraries. Datami additionally performed targeted manual testing of the vulnerable functionality.

    DonorUA is a nationwide initiative in the field of blood donation. The organization uses its own IT platform to search for donors, support hospitals, and assist patients.

    The client’s services process personal and medical data; therefore, cybersecurity is critical for DonorUA – any vulnerability may affect the stability of web resources and user trust.

    Tasks and challenges
    Despite following security best practices during development, DonorUA wanted to verify its web applications for potential vulnerabilities to ensure robust protection of users’ sensitive data.

    The organization turned to Datami and requested automated penetration testing of two platforms.
     
    • Conduct an automated pentest of the public website and the DonorUA user portal
    • Check the security of the web resources for vulnerabilities to enable timely remediation
    • Provide a detailed technical report describing identified threats and recommendations for mitigation
    icon
    Penetration testing
    Black-box testing of two DonorUA web applications using specialized security tools.
    icon
    Vulnerability assessment
    Analysis of functionality that may contain vulnerabilities and be exposed to potential cyberattacks.
    icon
    Report and recommendations
    Preparation of a detailed security report with findings and actionable improvement recommendations.

    Our approach

    For the DonorUA project, the Datami team applied a Black-box strategy and automated web application pentesting methods. We used several key tools, including Burp Suite, OWASP ZAP, Nessus, Nuclei, and Wapiti.

    After scanning the websites, we additionally performed manual testing of potentially vulnerable functionality. This allowed us to fully cover the attack surface and thoroughly investigate areas most susceptible to exploitation.

    Black-box

    Black-box

    Pentesting strategy without access to internal code – as close as possible to the actions of a real attacker
    Project stages

    First, Datami aligned with the client on critical security testing parameters, including scope, depth, permissions, and timelines. 

    Next, an automated pentest of the web applications was conducted.  With the remaining time, specialists additionally performed manual analysis of the most vulnerable areas, followed by detailed reporting.

    • Preparation
      Agreement on project details and key parameters. Selection of security testing strategy, methods, and tools.
    • Testing
      Automated Black-box pentest of the websites and manual verification of the most high-risk areas.
    • Analysis and reporting
      Creation of the final report describing detected vulnerabilities and providing recommendations for remediation.
    How we can help you?

    Every cybersecurity case study we solve involves deep analysis, tailored solutions, and measurable results.
    Datami has already helped over 600 companies strengthen their digital defenses — and we can do the same for your business.
    Ready to take action?

    Let’s start with a free consultation!
    Results and recommendations

    Results and recommendations

    Based on the testing of the public website and personal account of DonorUA, the Datami team identified 13 non-critical vulnerabilities:

    • 2 medium,
    • 9 low,
    • 2 informational.

    Among the detected issues were those related to technical aspects (for example, brute-force on the login page). The use of outdated JavaScript libraries and weak control of file uploads was also recorded.

    Based on the analysis, a technical report was prepared and recommendations for improving security were provided, in particular:

    • implement rate limits to prevent automated attacks;
    • regularly update the used libraries to the current versions;
    • optimize file-handling mechanisms: limit the types allowed for upload.

    Thus, DonorUA received a vision of the weak points of the web applications and an action plan for their elimination.

    Our certificates

    Datami is a cybersecurity firm whose qualifications are confirmed by 26 certifications and international standards. This allows us to perform tasks of varying complexity while complying with security, confidentiality, and ethical practice requirements.
    Project summary

    The project was completed within two weeks as planned. At the same time, a deeper assessment was performed than originally anticipated. Datami confirmed the absence of critical risks and a stable security level of DonorUA web applications.

    However, this case study demonstrated that even when security practices are followed during development, services may still contain vulnerabilities, and regular security audits for medical platforms remain extremely important.

    Level of risks
    Unknown
    13 non-critical vulnerabilities identified
    Critical vulnerabilities
    Unknown
    Not detected
    Timeline
    Planned – 2 weeks
    Completed on time, with additional manual analysis
    More success stories with Datami
    Browse other project case studies
    Cloudflare Zero Trust & SIEM for SaaS
    Cloudflare Zero Trust & SIEM for SaaS
    • MTTD reduced to 1–2 hours
    • False positives reduced by 50–65%
    Services:
    Cloudflare Zero Trust and Wazuh SIEM implementation
    Aug 4, 2026
    WordPress Website Recovery After a Hack
    WordPress Website Recovery After a Hack
    • Backdoor infections and web shells were completely removed.
    • 9 unauthorized admin accounts were removed.
    Services:
    WordPress Security Audit (White-box)
    Aug 4, 2026
    SIEM Wazuh Implementation for a Financial Company
    SIEM Wazuh Implementation for a Financial Company
    • PCI DSS & ISO 27001 audit-ready
    • Reduced false positives by 60–70%
    Services:
    SIEM Implementation (Wazuh)
    Jul 1, 2026
    Security image
    Ready to assess your project's security?
    Contact Datami — we’ll help you identify risks, strengthen your cybersecurity, and confidently pass certification.
    Datami articles
    Why AI Tokens Introduce a New Class of Smart Contract Risks Oleksandr Filipov
    Oleksandr Filipov
    Why AI Tokens Introduce a New Class of Smart Contract Risks

    A smart contract can pass a Solidity audit without a remark and still be exploitable - if part of the decision-making sits with a model. What a real audit with 40 findings reveals, and what to check before listing.

    4 min Aug 4, 2026
    When AI Meets Smart Contracts: How Prompt Injection Creates a New Web3 Attack Surface Oleksandr Filipov
    Oleksandr Filipov
    When AI Meets Smart Contracts: How Prompt Injection Creates a New Web3 Attack Surface

    A smart contract can pass the most rigorous audit and the product around it can still be exposed. All it takes is an AI reading on-chain text as a command. A new class of Web3 risk, from a real Datami finding.

    3 min Aug 3, 2026
    Cybersecurity Risk Self-Assessment: 6 Gaps Fintech Companies Notice Last Oleksandr Filipov
    Oleksandr Filipov
    Cybersecurity Risk Self-Assessment: 6 Gaps Fintech Companies Notice Last

    Most companies learn about their weak spots not from their own team, but from a due diligence partner or an attacker. We explain which gaps in fintech remain unnoticed the longest and why.

    4 min Jul 27, 2026
    Order a consultation
    We value your privacy
    We use cookies to enhance your browsing experience, serve personalized ads or content, and analyze our traffic. By clicking "Accept All", you consent to our use of cookies. Cookie policy