didsec has reached Level 4 with 75+ unique vulnerabilities discovered and they have proven to us that they understand web application vulnerabilities and how to discover them. If you run a bug bounty/vulnerability disclosure program and you are looking for an active, professional researcher, we recommend considering this user
Report Title | Event ID | Severity | Vulnerability Type |
---|---|---|---|
Admin Account takeover | FirstBlood v3 | CRITICAL | Auth issues |
xss on about.html | FirstBlood v3 | Medium | Reflective XSS |
CSRF in Modify Doctor | FirstBlood v3 | Low | Cross Site Request Forgery |
Open Redirect on logout.php | FirstBlood v3 | Low | Open Redirect |
Stored xss in HackerBack sign up phone number to Account takeover | FirstBlood v3 | CRITICAL | Stored XSS |
Reflected xss on doctors.php | FirstBlood v3 | Medium | Reflective XSS |
Blind xss on FirstBloodHackers INTERNAL ADMIN PANEL | FirstBlood v3 | CRITICAL | Stored XSS |
Stored xss in doctors name | FirstBlood v3 | High | Stored XSS |
Reflected xss on edit-doctor.php | FirstBlood v3 | Medium | Reflective XSS |
Stored xss on api/ambulances.php | FirstBlood v3 | High | Stored XSS |
Stored xss in doctors tagline | FirstBlood v3 | High | Stored XSS |
Stored xss in ambulance driver name | FirstBlood v3 | High | Stored XSS |
Unauthenticated user is able to change a doctors profile | FirstBlood v3 | High | Access control |
Able to delete an ambulance from an appointment | FirstBlood v3 | High | Access control |
Stored xss in doctors photo on meet_drs.php | FirstBlood v3 | High | Stored XSS |
Stored xss in doctors bio via about.php | FirstBlood v3 | High | Stored XSS |