We are busy working on a brand new website and platform. All of the content on this website is considered out-dated, however challenges and our members section are working as before. Stay tuned for updates!
| Report Title | Event ID | Severity | Vulnerability Type |
|---|---|---|---|
| Open redirect on logout | FirstBlood v1 | Low | Open Redirect |
| Doctor Invitation Code doesn't expire after first uage | FirstBlood v1 | High | Auth issues |
| New Doctors can use the api to get patients data | FirstBlood v1 | CRITICAL | Application/Business Logic |
| Event attendees leaked | FirstBlood v1 | CRITICAL | Information leak/disclosure |
| Bypass the invitation code and register your self as a doctor | FirstBlood v2 | Medium | Auth issues |
| Full Account takeover (even for admins) | FirstBlood v2 | CRITICAL | Application/Business Logic |
| newly created dr accounts can access patient PII via search api | FirstBlood v2 | Medium | Application/Business Logic |