didsec has reached Level 4 with 75+ unique vulnerabilities discovered and they have proven to us that they understand web application vulnerabilities and how to discover them. If you run a bug bounty/vulnerability disclosure program and you are looking for an active, professional researcher, we recommend considering this user
| Report Title | Event ID | Severity | Vulnerability Type |
|---|---|---|---|
| Admin Account takeover | FirstBlood v3 | CRITICAL | Auth issues |
| xss on about.html | FirstBlood v3 | Medium | Reflective XSS |
| CSRF in Modify Doctor | FirstBlood v3 | Low | Cross Site Request Forgery |
| Open Redirect on logout.php | FirstBlood v3 | Low | Open Redirect |
| Stored xss in HackerBack sign up phone number to Account takeover | FirstBlood v3 | CRITICAL | Stored XSS |
| Reflected xss on doctors.php | FirstBlood v3 | Medium | Reflective XSS |
| Blind xss on FirstBloodHackers INTERNAL ADMIN PANEL | FirstBlood v3 | CRITICAL | Stored XSS |
| Stored xss in doctors name | FirstBlood v3 | High | Stored XSS |
| Reflected xss on edit-doctor.php | FirstBlood v3 | Medium | Reflective XSS |
| Stored xss on api/ambulances.php | FirstBlood v3 | High | Stored XSS |
| Stored xss in doctors tagline | FirstBlood v3 | High | Stored XSS |
| Stored xss in ambulance driver name | FirstBlood v3 | High | Stored XSS |
| Unauthenticated user is able to change a doctors profile | FirstBlood v3 | High | Access control |
| Able to delete an ambulance from an appointment | FirstBlood v3 | High | Access control |
| Stored xss in doctors photo on meet_drs.php | FirstBlood v3 | High | Stored XSS |
| Stored xss in doctors bio via about.php | FirstBlood v3 | High | Stored XSS |