FirstBlood-#887Doctor Role can be obtained using leaked invite code
This issue was discovered on FirstBlood v2

On 2021-10-30, mrrootsec Level 2 reported:

Firstblood application is asking invite code when registering as a doctor. Invite code is being leaked in FirstBlood Scope & Policy .Using the leaked invite code anyone can register as doctor role.

Steps to Reproduce the Issue :

  1. Navigate to the FirstbloodV2 Program Scope and Policy
  2. If you read carefully at the Credentials available paragraph test is being highlighted in the policy

  3. Then go to the
  4. Provide any username and invite code from policy page and register. You can see the application validates the invite code and provide the access credentials

Impact :

  1. As an attacker using this leaked invite code,attacker can register as doctor role and can impersonate the user by doing malicious activities.

Remediaton / Fix :

  1. Invite code & Tokens should be restricted to the public users.

P3 Medium

FirstBlood ID: 24
Vulnerability Type: Auth issues

The old invite code was deleted but when testing FirstBlood v2 the developers accidentally left the test code working.