0xirfan has reached Level 4 with 75+ unique vulnerabilities discovered and they have proven to us that they understand web application vulnerabilities and how to discover them. If you run a bug bounty/vulnerability disclosure program and you are looking for an active, professional researcher, we recommend considering this user
| Report Title | Event ID | Severity | Vulnerability Type |
|---|---|---|---|
| Reflective XSS at /register.php | FirstBlood v2 | Medium | Reflective XSS |
| Reflective XSS at /login.php due to goto | FirstBlood v2 | Medium | Reflective XSS |
| Stored XSS on cancelled appointmnent message | FirstBlood v2 | High | Stored XSS |
| editpassword Function lead to ATO fore any users | FirstBlood v2 | High | Application/Business Logic |