We are getting close to releasing BugBountyHunter v2 which will introduce a brand new website, including member platforms, new features, challenges, guides, videos, and the long awaited zseano methodology v2. Right now, all of the content on this website is considered out-dated, however our members section continues to operate for members.
Stay tuned for updates coming soon!
| Report Title | Event ID | Severity | Vulnerability Type |
|---|---|---|---|
| XSS bypass on cancel report | FirstBlood v2 | High | Stored XSS |
| Admin account takeover by password reset | FirstBlood v2 | CRITICAL | Application/Business Logic |
| All vaccination proof records leaked | FirstBlood v2 | CRITICAL | Information leak/disclosure |
| Vaccine Login is vulnerable to SQLi | FirstBlood v2 | CRITICAL | SQL Injection |
| [BYPASS] Open URL Redirect on /drpanel/logout.php | FirstBlood v2 | Low | Open Redirect |
| [BYPASS] Newly registered Doctor can access to PII data | FirstBlood v2 | Medium | Application/Business Logic |
| [Collab] Unauthorized Access to Patients' PII at /api/ambulances.php | FirstBlood v3 | High | Information leak/disclosure |