FirstBlood-#1059Leak doctors private emails and internal data
This issue was discovered on FirstBlood v3



On 2022-12-08, iakdh Level 4 reported:

This endpoint /api/doctors.php leaks doctor emails and internal information like id and pending cases

Steps to reproduce:

  1. Go to /api/doctors.php

POC:

impact: information discolsure. Leak doctors private emails and internal data.

P2 High

Endpoint: /api/doctors.php

Parameter: NA

Payload: NA


FirstBlood ID: 66
Vulnerability Type: Information leak/disclosure

It is possible to leak doctors private information such as email and phone number via the /api/doctors.php endpoint. No authentication is needed.

Report Feedback

@zseano

Creator & Administrator


Congratulations you were the first user to discover this!