FirstBlood-#110Information Leak leads to full backend access
This issue was discovered on FirstBlood v1



On 2021-05-10, jonlaing Level 2 reported:

After running a google search on firstbloodhackers.com I came across the Reddit page which has post by someone revealing their Invitation Code.

https://www.reddit.com/r/BugBountyHunter/comments/n4xzw1/firstbloodhackerscom_doctor_registration/

From there we can register by entering our name and the invite code and it gives us an account.

P2 High

Parameter:

Payload:


FirstBlood ID: 15
Vulnerability Type: Auth issues

A doctors invite code is leaked on the internet which if used grants anyone access to the doctor portal. The invite code should expire after use.