ayush1098 has reached Level 4 with 75+ unique vulnerabilities discovered and they have proven to us that they understand web application vulnerabilities and how to discover them. If you run a bug bounty/vulnerability disclosure program and you are looking for an active, professional researcher, we recommend considering this user
Report Title | Event ID | Severity | Vulnerability Type |
---|---|---|---|
Change Password of admin user | FirstBlood v3 | CRITICAL | Auth issues |
Reflective XSS in appointment feature | FirstBlood v3 | Medium | Reflective XSS |
Open redirect still works on logout.php | FirstBlood v3 | Low | Open Redirect |
Reflected XSS at about.html | FirstBlood v3 | Medium | Reflective XSS |
Refelcted XSS at doctors.php | FirstBlood v3 | Medium | Reflective XSS |
Stored XSS on ambulance API | FirstBlood v3 | High | Stored XSS |
Reflected XSS at id parameter | FirstBlood v3 | Medium | Reflective XSS |
Stored XSS at meet_drs.pho | FirstBlood v3 | High | Stored XSS |
Blind XSS in username field | FirstBlood v3 | CRITICAL | Stored XSS |
Book non-bookable doctors in appointment | FirstBlood v3 | Low | Application/Business Logic |
Change Docto's image | FirstBlood v3 | High | Stored XSS |