FirstBlood-#1059 — Leak doctors private emails and internal data
This issue was discovered on FirstBlood v3
On 2022-12-08, iakdh Level 4 reported:
This endpoint /api/doctors.php leaks doctor emails and internal information like id and pending cases
Steps to reproduce:
- Go to /api/doctors.php
POC:

impact:
information discolsure. Leak doctors private emails and internal data.
P2 High
Endpoint: /api/doctors.php
Parameter: NA
Payload: NA
FirstBlood ID: 66
Vulnerability Type: Information leak/disclosure
It is possible to leak doctors private information such as email and phone number via the /api/doctors.php endpoint. No authentication is needed.
Creator & Administrator
Congratulations you were the first user to discover this!