We are getting close to releasing BugBountyHunter v2 which will introduce a brand new website, including member platforms, new features, challenges, guides, videos, and the long awaited zseano methodology v2. Right now, all of the content on this website is considered out-dated, however our members section continues to operate for members.
Stay tuned for updates coming soon!
| Report Title | Event ID | Severity | Vulnerability Type |
|---|---|---|---|
| Blind XSS on login page disclosing admin panel access | FirstBlood v3 | CRITICAL | Stored XSS |
| [COLLAB] Able to update profile picture of doctor | FirstBlood v3 | High | Stored XSS |
| Stored XSS leading to account takeover in admin user's dashboard via signing up for hackerback | FirstBlood v3 | CRITICAL | Stored XSS |
| DOM XSS on doctors.php via doctor parameter | FirstBlood v3 | Medium | Reflective XSS |