ibruteforce has reached Level 4 with 75+ unique vulnerabilities discovered and they have proven to us that they understand web application vulnerabilities and how to discover them. If you run a bug bounty/vulnerability disclosure program and you are looking for an active, professional researcher, we recommend considering this user
Report Title | Event ID | Severity | Vulnerability Type |
---|---|---|---|
Leak arbitrary users appointment details Manage/delete them | FirstBlood v1 | High | Insecure direct object reference |
Cancel arbitrary reports through 'aptid' parameter | FirstBlood v1 | High | Insecure direct object reference |
IDOR - Restricted doctor can view all the details of the patient such as contact details etc. | FirstBlood v1 | CRITICAL | Auth issues |
IDOR - Restricted user can view the details of hospital user. | FirstBlood v1 | CRITICAL | Application/Business Logic |
Potentially takeover other doctors account? | FirstBlood v1 | High | Auth issues |