axe


Rank #87 Level 4



76
unique bugs discovered
332 hours, 37 minutes and 8 seconds active hacking time

93
reports accepted
95 Accuracy

Vulnerability Types Found

Bug Submissions & total bug count


Hackevent (FirstBlood) Activity

Report Title Event ID Severity Vulnerability Type
The ref parameter is redirectable in the register.php path FirstBlood v2 Informative
Reflective XSS on register page FirstBlood v2 Medium Reflective XSS
XSS on login page FirstBlood v2 Medium Reflective XSS
Unexpected registered users FirstBlood v2 Medium Auth issues
Invalidate previously registered users by using duplicate invitations FirstBlood v2 Medium Auth issues
Cancel Stored XSS at the reservation function FirstBlood v2 High Stored XSS
Change user passwords at will to enable account takeover FirstBlood v2 CRITICAL Application/Business Logic
Regular accounts can override access to patient information FirstBlood v2 Medium Application/Business Logic
All user information is leaked due to unexpired cookies FirstBlood v2 Medium Application/Business Logic
Unauthorized modification of mailbox FirstBlood v2 Medium Application/Business Logic