FirstBlood-#509Weak unique invite code for registering doctor account
This issue was discovered on FirstBlood v2

On 2021-10-25, 0xconft Level 5 reported:

I tested that inviteCode parameter is accepting "test" as the invite code. and i can use this invite code to create doctor account. i can also use it again to create another account, but my previous account that i created with that invite code will be deleted


POST /register.php HTTP/1.1
                                        <div style="padding: 5px 5px 5px 5px; border: 2px solid green;">
                    Success! Your account has been created with the following credentials:
                    <b>Username: bobbuilder</b> <br> <b>Password: 1t60wIqPwP</b>

P3 Medium

Endpoint: /register.php

Parameter: inviteCode

Payload: test

FirstBlood ID: 24
Vulnerability Type: Auth issues

The old invite code was deleted but when testing FirstBlood v2 the developers accidentally left the test code working.