Someone wanted to learn this too, so Grasp built them a personal learning path.
Create your ownPenetration Testing
Module 2
Application Mapping and Test Planning
Module 3
Authentication and Session Security
Module 4
Access-Control Testing
Module 5
SQL and Operating-System Command Injection
Module 6
Cross-Site Scripting and Output Contexts
Module 7
Browser Trust Boundaries: CSRF, CORS, and Clickjacking
Module 8
Server-Side Input and File Handling
Module 9
REST API and Token Security Testing
Module 10
Business Logic, Race Conditions, and Exploit Chains
Module 11
Efficient Manual Testing and Lightweight Automation
Module 12
Professional Engagement, Reporting, and Job Portfolio