eliee has reached Level 4 with 75+ unique vulnerabilities discovered and they have proven to us that they understand web application vulnerabilities and how to discover them. If you run a bug bounty/vulnerability disclosure program and you are looking for an active, professional researcher, we recommend considering this user
Report Title | Event ID | Severity | Vulnerability Type |
---|---|---|---|
PrivEsc to root user on firstblood through deserialisation aided by unintended disclosure of composer installation | FirstBlood v2 | CRITICAL | Deserialization |
Stored XSS through DOB | FirstBlood v2 | Low | Stored XSS |
XSS through hidden `goto` parameter on `/login.php` | FirstBlood v2 | High | Reflective XSS |
Application logic error on /drpanel/ leads to ATO of doctors who have never signed in | FirstBlood v2 | High | Application/Business Logic |