{"id":"c7b5aff2-bce3-4353-8e86-1f86e3892e9c","engagementId":"37dbffd8-cc4f-47c1-928d-a4119bfd5f48","data":{"brief":{"id":"25130578-2549-4ea8-b5b4-e00f4afe10b3","name":"Bupa Australia Vulnerability Disclosure Engagement","tagline":"Hospitals and Health Care","description":"\u003cp\u003eBupa is a health and care company committed to helping our customers live longer, healthier, happier lives and making a better world. We offer a broad range of services, including aged care and retirement, dental, optical, health insurance, and community wellbeing initiatives, to improve\u003cbr\u003e\nthe health of all Australians.\u003c/p\u003e\n\n\u003cp\u003eThis Vulnerability Disclosure Program (VDP) provides security researchers with a safe, legal process to report security vulnerabilities affecting Bupaʼs public digital assets. This is a coordinated disclosure program and does not provide monetary rewards unless otherwise\u003cbr\u003e\nstated.\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/p\u003e\n\n\u003ch2\u003eEligibility\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou must be a resident of a country that is not under Australian or U.S. sanctions\u003c/li\u003e\n\u003cli\u003eYou are not currently (or have been in the last 12 months) an employee of Bupa, a Bupa subsidiary, or a third-party contractor with access to Bupaʼs internal systems and networks, or the related design, architecture and configuration details\u003c/li\u003e\n\u003c/ul\u003e","industryTagId":"50214b57-2dde-40fd-ae5a-6680372523d4","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Bupa not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Bupa, you can report it to this engagement However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eEngagement Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWe do not accept reports that contain low-effort or AI-generated content. Submissions must demonstrate original analysis, clear understanding of the issue, and actionable detail. Reports lacking meaningful human input will be rejected\u003c/li\u003e\n\u003cli\u003ePotential post-exploitation scenarios: If you believe you've identified a vulnerability that may lead to post-exploitation activity including modification or destruction of data please stop testing and submit your finding. We will work with you to evaluate the vulnerability and award you accordingly for the final impact and severity\u003c/li\u003e\n\u003cli\u003eYou are testing on production. Behavior that compromises the stability and integrity of the target(s) is out of scope.\n\n\u003cul\u003e\n\u003cli\u003e For example, do not target other users' data (use one of your other sets of credentials), delete/remove/edit parts of the site, engage any sort of DoS attack, and/or compromise any target's ability to function for other users. If you believe that you have found a vulnerability of this nature, please stop further testing and report it\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAutomated tools and scripts may be used responsibly, provided they do not cause service degradation, outage or excessive traffic\u003c/li\u003e\n\u003cli\u003eIf the identification of a vulnerability provides access to sensitive data, such as Personal Identifiable Information (PII), Payment Card Information (PCI), Private Health Record (PHI) or proprietary information, immediately cease testing and report the vulnerability. Do not take any screenshots or copy of the data and do not perform any actions that can alter the data\u003c/li\u003e\n\u003cli\u003eAll vulnerability reports must be submitted through Bugcrowd. Bupa does not accept vulnerability reports via email, social media, or customer support channels\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eBupa VDP (Vulnerability Disclosure Program) has a strict non-disclosure policy. No vulnerability is to be displayed in any public domain\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eReport Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities discovered on multiple paths, endpoints, parameters will be treated as duplicates. This includes findings across different environments (e.g., development, staging, production) unless the impact or exploitation method is materially different. Please submit only one report\u003c/li\u003e\n\u003cli\u003eReports must contain the role used for testing, a clear explanation of the issue and the security impact along with detailed steps to reproduce it. If the issue cannot be reliably reproduced based on your report, it may be considered ineligible for a reward\u003c/li\u003e\n\u003cli\u003eDo not submit more than one vulnerability per report. In cases where demonstrating impact requires chaining multiple vulnerabilities together, those can be included in the same report as long as the linkage is clearly explained\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess\u003c/h2\u003e\n\n\u003cp\u003eAll targets within scope of testing are publicly accessible. \u003c/p\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003eTo gain access to the applications, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cp\u003eTo support your testing, we’ve highlighted several key areas of interest. While we ask that you report any efforts related to these areas, please note that testing is not limited to them. Submissions outside of these focus areas are equally welcomed and appreciated.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eOWASP Top 10 Vulnerabilities\u003c/li\u003e\n\u003cli\u003eAuthentication Issues\u003c/li\u003e\n\u003cli\u003eSQL Injection\u003c/li\u003e\n\u003cli\u003eBroken Authentication\u003c/li\u003e\n\u003cli\u003eBroken Access Control\u003c/li\u003e\n\u003cli\u003eCross-Site Scripting\u003c/li\u003e\n\u003cli\u003eCross-Site Request Forgery\u003c/li\u003e\n\u003cli\u003eInjection vulnerabilities\u003c/li\u003e\n\u003cli\u003eIdentification of private keys and sensitive data\u003c/li\u003e\n\u003cli\u003eSecurity control misconfigurations\u003c/li\u003e\n\u003cli\u003eSub-domain take-over (passive verification only without taking over sub-domain)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eExcluded Submission Types\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eP5 vulnerabilities\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCredential Stuffing/Password Spraying attacks\u003c/li\u003e\n\u003cli\u003eAvailability/volumetric testing e.g.:\n\n\u003cul\u003e\n\u003cli\u003eDoS/DDoS/Network DoS\u003c/li\u003e\n\u003cli\u003eRate limiting bypass attempts\u003c/li\u003e\n\u003cli\u003eEmail bombing or flooding\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eDMARC/SPF Issues\u003c/li\u003e\n\u003cli\u003eThird party integrations\u003c/li\u003e\n\u003cli\u003eAny attacks which may impact the usability or degrade performance of customer facing services\u003c/li\u003e\n\u003cli\u003eALL forms of social Engineering\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our \u003ca href=\"https://www.bugcrowd.com/resources/hacker-resources/standard-disclosure-terms/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eTerms \u0026amp; Conditions\u003c/a\u003e  that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via our \u003ca href=\"https://bugcrowd-support.freshdesk.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eFreshdesk Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"c168e39e-a0f8-42d7-9827-e6d080748c95","name":"In Scope ","targets":[{"id":"2e4fa942-4da6-4f53-84e2-7440dd4ba15b","uri":"","name":"https://partnerlogin.bupa.com.au/*","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"32e4b220-e6fc-41eb-8e74-5a7b26a95cac","sortOrder":0},"sortOrder":0,"tags":[{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"2e4fa942-4da6-4f53-84e2-7440dd4ba15b"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"2e4fa942-4da6-4f53-84e2-7440dd4ba15b"}],"recentChangeFlags":null},{"id":"f3741a7b-706a-40a0-b9e0-24aa4ff86dd6","uri":"","name":"https://my.bupa.com.au/*","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e3b8d692-6e62-42a8-80d8-12ee5f81c256","sortOrder":1},"sortOrder":1,"tags":[{"id":"68da3fae-5355-463e-8442-9a5016b1bda0","name":"ASP.NET","targetId":"f3741a7b-706a-40a0-b9e0-24aa4ff86dd6"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"f3741a7b-706a-40a0-b9e0-24aa4ff86dd6"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"f3741a7b-706a-40a0-b9e0-24aa4ff86dd6"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"f3741a7b-706a-40a0-b9e0-24aa4ff86dd6"}],"recentChangeFlags":null},{"id":"e5510519-712e-42af-82df-564087c479c6","uri":"","name":"https://account.bupa.com.au/*","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f43a9df8-e1ec-4a88-a7e3-11ae917f78e4","sortOrder":2},"sortOrder":2,"tags":[{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"e5510519-712e-42af-82df-564087c479c6"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"e5510519-712e-42af-82df-564087c479c6"}],"recentChangeFlags":null},{"id":"92a19470-cf04-422f-b978-63081a2949a6","uri":"https://play.google.com/store/apps/details?id=au.com.bupa.blua\u0026hl=en","name":"Bupa - Google Play","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"68d64867-16ce-43a7-af13-dedaa94e3361","sortOrder":3},"sortOrder":3,"tags":[{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"92a19470-cf04-422f-b978-63081a2949a6"}],"recentChangeFlags":null},{"id":"8c3c0032-603f-4911-8b15-a816089ca7cf","uri":"https://apps.apple.com/au/app/blua/id1620073582","name":"Bupa - iOS","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1fcb76e8-9929-4d74-9d7e-97f1e5e40de4","sortOrder":4},"sortOrder":4,"tags":[{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"8c3c0032-603f-4911-8b15-a816089ca7cf"}],"recentChangeFlags":null},{"id":"bdf79312-d874-4390-b26f-2e9821650e2b","uri":"https://play.google.com/store/apps/details?id=bupa.ProviderFinder","name":"myBupa - Google Play ","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2185b66e-a6a5-4ec1-87f9-a082ce1c788a","sortOrder":5},"sortOrder":5,"tags":[{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"bdf79312-d874-4390-b26f-2e9821650e2b"}],"recentChangeFlags":null},{"id":"98ce52f3-d4f5-481b-bde5-5b63c87888f2","uri":"https://apps.apple.com/au/app/mybupa/id475542225","name":"myBupa - iOS","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"affef7e9-2ef5-40c1-9fcd-c2284ce63fa1","sortOrder":6},"sortOrder":6,"tags":[{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"98ce52f3-d4f5-481b-bde5-5b63c87888f2"}],"recentChangeFlags":null},{"id":"586914d2-b936-4131-bf24-4e034a0f5ca7","uri":"","name":"https://bupaagedcare.com.au/*","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"4e57f22a-219d-4e94-8fbe-f837f457521a","sortOrder":7},"sortOrder":7,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"586914d2-b936-4131-bf24-4e034a0f5ca7"},{"id":"624f911d-7e8c-4d56-b523-e7416c1cc319","name":"NextJS","targetId":"586914d2-b936-4131-bf24-4e034a0f5ca7"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"586914d2-b936-4131-bf24-4e034a0f5ca7"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"586914d2-b936-4131-bf24-4e034a0f5ca7"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"586914d2-b936-4131-bf24-4e034a0f5ca7"}],"recentChangeFlags":null},{"id":"b5669543-5ceb-4112-ab93-455bee5dd926","uri":"","name":"https://bupaoptical.bupa.com.au/*","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"48657604-7315-4a86-a7ee-aeba88399a1c","sortOrder":8},"sortOrder":8,"tags":[{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"b5669543-5ceb-4112-ab93-455bee5dd926"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"b5669543-5ceb-4112-ab93-455bee5dd926"}],"recentChangeFlags":null},{"id":"c29fa21e-a497-4347-9f4a-24d3c09b55b5","uri":"","name":"https://bupadental.com.au/*","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ae4c668d-4a59-41cb-8d9f-03d894f63274","sortOrder":9},"sortOrder":9,"tags":[{"id":"68da3fae-5355-463e-8442-9a5016b1bda0","name":"ASP.NET","targetId":"c29fa21e-a497-4347-9f4a-24d3c09b55b5"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"c29fa21e-a497-4347-9f4a-24d3c09b55b5"}],"recentChangeFlags":null},{"id":"dcd03868-678d-4cad-a2f2-cd28313c3a3d","uri":"","name":"https://blua.bupa.com.au/*","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"30e49bd1-848b-4f03-87ee-23b9ad9099c5","sortOrder":10},"sortOrder":10,"tags":[{"id":"624f911d-7e8c-4d56-b523-e7416c1cc319","name":"NextJS","targetId":"dcd03868-678d-4cad-a2f2-cd28313c3a3d"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"dcd03868-678d-4cad-a2f2-cd28313c3a3d"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"dcd03868-678d-4cad-a2f2-cd28313c3a3d"}],"recentChangeFlags":null},{"id":"2ec6a13b-6782-4718-9ebb-b7204ba5fbef","uri":"","name":"https://bupa.com.au/*","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"15bd7abe-0ca0-4a14-80a9-e0cc347b65bd","sortOrder":11},"sortOrder":11,"tags":[{"id":"68da3fae-5355-463e-8442-9a5016b1bda0","name":"ASP.NET","targetId":"2ec6a13b-6782-4718-9ebb-b7204ba5fbef"},{"id":"a5bf7fc5-03c4-42f4-b10d-5ceb23d1c064","name":"Lodash","targetId":"2ec6a13b-6782-4718-9ebb-b7204ba5fbef"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"2ec6a13b-6782-4718-9ebb-b7204ba5fbef"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003ch2\u003eTarget Information\u003c/h2\u003e\n\n\u003cp\u003eAll listed applications and targets are our digital channels used to deliver healthcare and health insurance related services to our customers and partners.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"37dbffd8-cc4f-47c1-928d-a4119bfd5f48","code":"bupa-aus-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"6a1edd3c-98df-4c99-bede-8ff13eca0596","startsAt":"2026-04-28T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Healthcare","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/4070/d69c/489ddc38/69a52f581a317b381bd7d97ccfe1d75d_bupa_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2026-04-28T18:00:00.026Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/bupa-aus-vdp-pro","changelogs":"/engagements/bupa-aus-vdp-pro/changelog","submissions":null,"announcements":"/engagements/bupa-aus-vdp-pro/announcements","hallOfFame":"/engagements/bupa-aus-vdp-pro/hall_of_fames","crowdstream":"/engagements/bupa-aus-vdp-pro/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/bupa-aus-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=bupa-aus-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/bupa-aus-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/bupa-aus-vdp-pro/changelog","publishedAt":"2026-04-29T02:45:36.711Z","engagementChangelogUrl":"/engagements/bupa-aus-vdp-pro/changelog/c7b5aff2-bce3-4353-8e86-1f86e3892e9c","createUserFeedbacksUrl":"/engagements/bupa-aus-vdp-pro/feedbacks","engagementCrowdstreamUrl":"/engagements/bupa-aus-vdp-pro/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}