c3phas has reached Level 4 with 75+ unique vulnerabilities discovered and they have proven to us that they understand web application vulnerabilities and how to discover them. If you run a bug bounty/vulnerability disclosure program and you are looking for an active, professional researcher, we recommend considering this user
Report Title | Event ID | Severity | Vulnerability Type |
---|---|---|---|
Information Disclosure allowing an attacker to register as a doctor | FirstBlood v1 | High | Auth issues |
Application Logic allowing access to unauthorised information belonging to patients | FirstBlood v1 | CRITICAL | Application/Business Logic |
Application Logic Issue allowing a doctor who is not authorised to view patients information on the dashboard | FirstBlood v1 | CRITICAL | Application/Business Logic |
Un-Authorized users can access "/drpanel/drapi/qp.php" endpoint and access users personal information | FirstBlood v2 | Medium | Application/Business Logic |
A chain of two open redirects to leak some users token | FirstBlood v2 | High | Reflective XSS |
Insecure Deserialization leading to Remote Code Execution | FirstBlood v2 | CRITICAL | Deserialization |