jomar has reached Level 4 with 75+ unique vulnerabilities discovered and they have proven to us that they understand web application vulnerabilities and how to discover them. If you run a bug bounty/vulnerability disclosure program and you are looking for an active, professional researcher, we recommend considering this user
| Report Title | Event ID | Severity | Vulnerability Type |
|---|---|---|---|
| Leak PII through the events API | FirstBlood v1 | CRITICAL | Information leak/disclosure |
| [COLLAB] Stored XSS on message param through appointment annulation allow admin ATO | FirstBlood v1 | CRITICAL | Stored XSS |
| [COLLAB] Query appointment with simple ID / Bypass front end restriction | FirstBlood v1 | High | Insecure direct object reference |