I got the penetration test report yesterday. Got confused trying to read it. Some vulnerabilities are marked 'Low', some 'Medium', and at the end there are two 'High' risks.
For example, one says 'SQL injection possible', the other 'outdated SSL version'. One looks very serious but both are marked as the same 'high' risk. How many vulnerabilities do i need to fix?
I sent it to the developer and we're arguing about 'what does this mean'. One says 'it's not serious' the other says 'shut down the site'. How should i interpret the report?