We are getting close to releasing BugBountyHunter v2 which will introduce a brand new website, including member platforms, new features, challenges, guides, videos, and the long awaited zseano methodology v2. Right now, all of the content on this website is considered out-dated, however our members section continues to operate for members.
Stay tuned for updates coming soon!
FirstBlood-#1059 — Leak doctors private emails and internal data
This issue was discovered on FirstBlood v3
On 2022-12-08, iakdh Level 4 reported:
This endpoint /api/doctors.php leaks doctor emails and internal information like id and pending cases
Steps to reproduce:
- Go to /api/doctors.php
POC:

impact:
information discolsure. Leak doctors private emails and internal data.
P2 High
Endpoint: /api/doctors.php
Parameter: NA
Payload: NA
FirstBlood ID: 66
Vulnerability Type: Information leak/disclosure
It is possible to leak doctors private information such as email and phone number via the /api/doctors.php endpoint. No authentication is needed.
Report Feedback
Creator & Administrator
Congratulations you were the first user to discover this!