{"id":"93ea9025-907e-485e-b7a5-91709d64e741","engagementId":"9ad4feaf-b418-49b2-9559-3c8b48f0c175","data":{"brief":{"id":"86fcb975-bd34-46d2-b5f1-312ad7bcf6e7","name":"Dell Technologies Application Bug Bounty","tagline":"Giving you what you need to securely connect, produce, and collaborate; anywhere at any time.","description":"\u003cp\u003eDell Technologies (\"Dell\") recognizes the value of the security community to create a more secure world and welcomes the opportunity to collaborate with community members who share this common goal.\u003c/p\u003e\n\n\u003cp\u003eThis bug bounty program (the “Bug Bounty Program”) is limited to those security vulnerabilities identified within the dell.com and delltechnologies.com pages listed as in scope the Targets section below. Please carefully review inclusions and exclusions detailed in the sections below.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eNote:\u003c/strong\u003e All other Dell products, applications and online properties are excluded from this Bug Bounty Program. \u003c/p\u003e\n\n\u003ch3\u003eRatings/Rewards\u003c/h3\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher. Please see below for any exceptions from the standard VRT.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003eDell does not accept or make payment for reports of stolen or compromised credentials that are sourced from sanctioned entities, sanctioned individuals, or sanctioned locations. Dell will request affirmation from the researcher that the credentials were not obtained through a source to which the researcher paid money or other consideration.\u003c/p\u003e\n\n\u003cp\u003eFor submissions regarding GitHub Credentials, all findings will be initially rated as a P5. Once the finding has been determined to have a real impact, it will be upgraded accordingly. Remember, it is beneficial to include the sensitive information in your finding along with the link to help speed up the validation process.\u003c/p\u003e\n\n\u003cp\u003eVulnerabilities in Dell websites and services not explicitly out of scope or explicitly in scope of this program will be rated as a P5.\u003c/p\u003e\n\n\u003ch3\u003eReporting Requirements\u003c/h3\u003e\n\n\u003cp\u003eWhen reporting an issue to this program, please be sure to include the following:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe description, VRT, Target, and Bug URL fields should all be filled in.\u003c/li\u003e\n\u003cli\u003eDetailed replication steps (how to replicate this issue - in a step by step manner that could be followed by even non security-involved persons)\u003c/li\u003e\n\u003cli\u003eA real-world exploit scenario (elaborate on WHAT an attacker could do with this vulnerability, and HOW they would go about doing so - please do not deal in extreme hypotheticals - e.g. those that would require the intervention of a nation-state, etc)\u003c/li\u003e\n\u003cli\u003eWhen testing functionality using forums or other public-facing areas, please ensure that any dummy data you create, or control is removed once testing is complete. This helps maintain the integrity of our system.\u003c/li\u003e\n\u003c/ul\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as In-Scope. \u003cem\u003eAny domain/property of Dell not listed in the targets section is out of scope. This includes any/all subdomains not listed above.\u003c/em\u003e If you believe you've identified a vulnerability on a system outside the scope, please submit to this program.  These types of findings will be initially triaged as a P5 informational only.\u003c/p\u003e\n\n\u003ch3\u003eTarget Information\u003c/h3\u003e\n\n\u003ch4\u003eWeb Applications\u003c/h4\u003e\n\n\u003cp\u003eAll URLs listed in the In scope Targets section above are publicly accessible web applications. Researchers are invited to test all aspects of these applications. Please use a custom HTTP header in all your traffic while testing. \u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eIdentifier\u003c/th\u003e\n\u003cth\u003eFormat\u003c/th\u003e\n\u003cth\u003eExample\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eUsername\u003c/td\u003e\n\u003ctd\u003eX-Bug-Bounty: Bugcrowd-\u0026lt;username\u0026gt;\u003c/td\u003e\n\u003ctd\u003eX-Bug-Bounty:Bugcrowd-MDell\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003ch4\u003eCheckout Process Testing\u003c/h4\u003e\n\n\u003cp\u003eThe focus of this Bug Bounty Program is intended to be on the consumer shopping and buying experience. When testing the Checkout process, please note the following: \u003c/p\u003e\n\n\u003cp\u003e1) Creating an account is optional, you may also checkout as a Guest;\u003cbr\u003e\n2) You are able to enter dummy data throughout the checkout process (Name, Address, Credit Card). Payment data is not verified until the order is reviewed and submitted. \u003cstrong\u003eOnce you get to the Review page, do NOT click the Submit Order button.\u003c/strong\u003e \u003c/p\u003e\n\n\u003cp\u003eNOTE: Any valid purchases made are not eligible for reimbursement as part of this Bug Bounty Program. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eFocus Areas\u003c/h3\u003e\n\n\u003cp\u003eWe are looking for any vulnerability that could negatively affect both the security of our company and that of our customers. The main categories of vulnerabilities that we look for are the following:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eRemote code execution as root\n\n\u003cul\u003e\n\u003cli\u003eFor any remote code execution, avoid uploading any active web shells, or persistence for the validation of bugs, and instead retrieve a hostname, and username for proof of your vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eRemote root login\u003c/li\u003e\n\u003cli\u003eRemote configuration injections\u003c/li\u003e\n\u003cli\u003eLocal privilege escalations\u003c/li\u003e\n\u003cli\u003eUnauthorized access to sensitive data\u003c/li\u003e\n\u003cli\u003eDirect exposure of highly sensitive customer data to unauthorized parties, for example:\n\n\u003cul\u003e\n\u003cli\u003eDevice secrets\u003c/li\u003e\n\u003cli\u003eCryptographic keys\u003c/li\u003e\n\u003cli\u003eCustomer credentials or PII\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eCross-site Scripting (XSS)\u003c/li\u003e\n\u003cli\u003eCross-site Request Forgery\u003c/li\u003e\n\u003cli\u003eServer-Side Request Forgery (SSRF)\u003c/li\u003e\n\u003cli\u003eSQL Injection\u003c/li\u003e\n\u003cli\u003eRemote Code Execution (RCE)\u003c/li\u003e\n\u003cli\u003eXML External Entity Injection (XXE) with significant impact\u003c/li\u003e\n\u003cli\u003eAccess Control Issues\u003c/li\u003e\n\u003cli\u003eAuthentication Bypass Issues (note: check for exceptions in Excluded Submission Types)\u003c/li\u003e\n\u003cli\u003eAuthorization Flaws\u003c/li\u003e\n\u003cli\u003ePrivilege Escalation\u003c/li\u003e\n\u003cli\u003eDirectory Traversal Issues\u003c/li\u003e\n\u003cli\u003eSensitive Information Disclosure\u003c/li\u003e\n\u003cli\u003eData Exposure\u003c/li\u003e\n\u003cli\u003eBusiness Logic Vulnerabilities\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eExcluded Submission Types\u003c/h3\u003e\n\n\u003cp\u003eThis program follows the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e with some additional submission types we consider to be excluded below. Dell will not provide rewards for such submissions:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eFailure to invalidate session for SSO\u003c/li\u003e\n\u003cli\u003eSubmissions related to DMARC\u003c/li\u003e\n\u003cli\u003eMissing SPF Records\u003c/li\u003e\n\u003cli\u003eNo rate limiting or CAPTCHA\u003c/li\u003e\n\u003cli\u003eSubmissions for 3rd party sites where Dell does not own the application\u003c/li\u003e\n\u003cli\u003eOut of date software versions without impact\u003c/li\u003e\n\u003cli\u003eDisclosure of known public files or directories, (e.g. robots.txt)\u003c/li\u003e\n\u003cli\u003eClickjacking and issues only exploitable through clickjacking\u003c/li\u003e\n\u003cli\u003eExposure of API keys with no security impact, or where the only impact is exhausting of API quotas\u003c/li\u003e\n\u003cli\u003eInternal IP address disclosure\u003c/li\u003e\n\u003cli\u003eStack traces displayed on error pages instead of generic error messages\u003c/li\u003e\n\u003cli\u003eComponent or technology (e.g. PHP, ASP.NET, etc.) usage is revealed\u003c/li\u003e\n\u003cli\u003eApplication allowing username enumeration or user email enumeration\u003c/li\u003e\n\u003cli\u003eLogin or Forgot Password page brute force, account lockout not enforced, or insufficient password strength requirements\u003c/li\u003e\n\u003cli\u003eMalicious file uploads not affecting application server\u003c/li\u003e\n\u003cli\u003eCookies not set with HTTPOnly or secure flag\u003c/li\u003e\n\u003cli\u003eCSV formula injection\u003c/li\u003e\n\u003cli\u003eAny missing defense-in-depth security measures which cannot be exploited without the existence of some other weakness\u003c/li\u003e\n\u003cli\u003eReports for assets that are vulnerable to new CVEs that have been in a PUBLISHED status less that 5 business days or a 0-days will be eligible for reward only if we act based on the report. The report will not be eligible for reward if the asset previously reported and remediation has been planned.\u003c/li\u003e\n\u003cli\u003eReports for credential and token leaks found in third party sites will not be accepted without strong evidence that the data is valid. The reports will also need to provide strong evidence that the leaked data is owned by Dell.\u003c/li\u003e\n\u003cli\u003eDenial of service (DoS) attacks\u003c/li\u003e\n\u003cli\u003eFindings as reported by automated tools without additional analysis as to how and what is vulnerable\u003c/li\u003e\n\u003cli\u003eOpen ports without an accompanying proof-of-concept (POC) demonstrating a vulnerability\u003c/li\u003e\n\u003cli\u003eVulnerabilities only affecting users of outdated or unpatched browsers\u003c/li\u003e\n\u003cli\u003eSpam reports\u003c/li\u003e\n\u003cli\u003ePhishing and social engineering reports\u003c/li\u003e\n\u003cli\u003eOpen redirect on SonicWall or similar devices\u003c/li\u003e\n\u003cli\u003eBroken link hijacking on social media accounts\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eProgram Rules\u003c/h3\u003e\n\n\u003ch4\u003eLegal Terms:\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eBy participating in this Bug Bounty Program, you agree to be bound to the terms of this program brief (“Dell Terms \u0026amp; Conditions”).\u003c/li\u003e\n\u003cli\u003eThese terms constitute the entire agreement between you and Dell and are governed by Texas law. Any changes to these terms must be in writing.\u003c/li\u003e\n\u003cli\u003eThe intent of this Bug Bounty Program is to encourage coordinated disclosure between you and Dell. Unless required by federal law or local law enforcement, Dell does not intend to pursue litigation against research and disclosure that meets the Dell Terms \u0026amp; Conditions.\u003c/li\u003e\n\u003cli\u003eIf legal action is initiated by a third party against you relative to the Bug Bounty Program and you are in full compliance with the Dell Terms \u0026amp; Conditions, Dell may at its sole discretion take reasonable steps to help make it known that your actions were conducted in compliance with this program.\u003c/li\u003e\n\u003cli\u003eDell will not publicly disclose the identity of any researcher without their consent, except where required by law.\u003c/li\u003e\n\u003cli\u003eDell reserves the right to change or modify the Dell Terms \u0026amp; Conditions at any time. Please check for any updates to this program brief before creating a new submission.\u003c/li\u003e\n\u003cli\u003eBy participating in this Bug Bounty Program, you waive any rights to the confidentiality of the submitted work and, further, you agree to grant Dell an irrevocable, worldwide, royalty-free, perpetual and transferable license to use the submitted research, disclosure and materials and you waive any claims against Dell based on Dell’s license or the rights granted.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eDisclosure:\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eThis program does not allow researchers to disclose the results of a submission.\u003c/li\u003e\n\u003cli\u003ePublic disclosures will make the researcher ineligible for future participation in this or other disclosure or bug bounty programs by Dell.\u003c/li\u003e\n\u003cli\u003eRewards will not be given for submissions which are publicly disclosed.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eRewards:\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eThis program does not offer rewards for out-of-scope targets or excluded submission types.\u003c/li\u003e\n\u003cli\u003eDell will not negotiate in response to duress or threats (e.g., we will not negotiate the payout amount under threat of withholding the vulnerability or threat of releasing the vulnerability or any exposed data to the public).\u003c/li\u003e\n\u003cli\u003eIf multiple reports are received for the same issue attributed, the reward will be awarded to the earliest report containing enough information to reproduce. Dell will not offer rewards for previously known issues. Dell determines duplicates at its sole discretion and will not share details on other reports.\u003c/li\u003e\n\u003cli\u003eIdentical issues across different production and non-production environment counterparts will be considered duplicates.\u003c/li\u003e\n\u003cli\u003eIdentical issues across different sub domains that share code will be considered duplicates.\u003c/li\u003e\n\u003cli\u003eResearchers with valid reports will be awarded platform points and listed on \u003ca href=\"https://bugcrowd.com/dell/hall-of-fame\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eDell’s Bugcrowd Hall of Fame\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eTesting:\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eUse only your assigned account for testing purposes. Do not attempt to gain access to other user’s accounts or compromise any user or Dell confidential information.\u003c/li\u003e\n\u003cli\u003eTesting must not violate any applicable laws or regulations or disrupt or compromise any data that is not your own. If you inadvertently cause a violation or disruption (such as accessing the data of other users, service configurations, or other confidential information) while testing, please report the incident immediately to \u003ca href=\"mailto:secure@dell.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003esecure@dell.com\u003c/a\u003e. Any data accessed during your testing must not be used, disclosed, stored, or recorded in any way.\u003c/li\u003e\n\u003cli\u003eDo not exploit a vulnerability you discover beyond what is needed to obtain the proof of concept.\u003c/li\u003e\n\u003cli\u003eAutomated vulnerability scanning tools are strictly prohibited as part of this and any other Dell program.\u003c/li\u003e\n\u003cli\u003eDenial of Service (DoS) and Distributed Denial of Service (DDoS) based attacks are strictly prohibited as part of this and any other Dell program.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eEligibility\u003c/h4\u003e\n\n\u003cp\u003eYou are not eligible to participate in this bug bounty program if you are: \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eA current employee of Dell or a Dell subsidiary, or an immediate family (parent, sibling, spouse, or child) or household member of such an employee. \u003c/li\u003e\n\u003cli\u003eA contingent staff member, contractor or vendor employee currently working with Dell. \u003c/li\u003e\n\u003cli\u003eA former employee or contractor of Dell who was involved in the development or testing of the Dell product listed as the target in the Bug Bounty Program.\u003c/li\u003e\n\u003cli\u003eLocated in a non-United States export/trade sanction country.\u003c/li\u003e\n\u003c/ul\u003e","safeHarborStatus":null,"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"847f5a6c-170f-4a22-a637-b6394219e3bb","name":"In Scope","targets":[{"id":"1d276c9d-e1e9-4c5a-bc9e-736bdfde6b27","uri":null,"name":"*.dell.com/*","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"4c53c295-2723-48bc-88c2-dfdbd35154d7","sortOrder":0},"sortOrder":0,"tags":[{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"1d276c9d-e1e9-4c5a-bc9e-736bdfde6b27"},{"id":"6481be19-8d64-4bb2-8426-2f1f7afe32e6","name":"Modernizr","targetId":"1d276c9d-e1e9-4c5a-bc9e-736bdfde6b27"},{"id":"68da3fae-5355-463e-8442-9a5016b1bda0","name":"ASP.NET","targetId":"1d276c9d-e1e9-4c5a-bc9e-736bdfde6b27"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"1d276c9d-e1e9-4c5a-bc9e-736bdfde6b27"},{"id":"b6333057-ce1f-4205-bcb6-ce56be83543b","name":"Microsoft IIS","targetId":"1d276c9d-e1e9-4c5a-bc9e-736bdfde6b27"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"1d276c9d-e1e9-4c5a-bc9e-736bdfde6b27"}],"recentChangeFlags":null},{"id":"cb0c73ca-0ab6-4e68-ae91-e87c6ed115bf","uri":"","name":"*.delltechnologies.com/* ","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6b9787aa-5fd7-4570-9366-aecd2995765b","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"cb0c73ca-0ab6-4e68-ae91-e87c6ed115bf"}],"recentChangeFlags":null},{"id":"d20bbbb3-3713-4816-81df-68033361424c","uri":"https://console.delltechnologies.com/nav/administration","name":"https://console.delltechnologies.com/nav/administration","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"bca465a8-de19-4fdc-bd53-a024ad742330","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"d20bbbb3-3713-4816-81df-68033361424c"}],"recentChangeFlags":null},{"id":"d00a8efe-970b-4f01-9139-b7587fdcf463","uri":"https://console.delltechnologies.com/nav/invoice","name":"https://console.delltechnologies.com/nav/invoice","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e60a6d5d-02dd-485c-8a46-d5b6b651f2cf","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"d00a8efe-970b-4f01-9139-b7587fdcf463"}],"recentChangeFlags":null},{"id":"4322b21b-65e2-4ca1-9ad5-8317652e8d94","uri":"https://console.delltechnologies.com/nav/billing","name":"https://console.delltechnologies.com/nav/billing","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"454b1738-9edb-4b45-8e06-5678a8735cdf","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"4322b21b-65e2-4ca1-9ad5-8317652e8d94"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"8408eac2-2c0c-4f03-9662-e2afbfefdf45","p1MaxCents":250000,"p1MinCents":210000,"p2MaxCents":150000,"p2MinCents":120000,"p3MaxCents":75000,"p3MinCents":50000,"p4MaxCents":10000,"p4MinCents":5000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":2100,"max":2500},"2":{"min":1200,"max":1500},"3":{"min":500,"max":750},"4":{"min":50,"max":100},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"ffade093-7552-4132-b007-50d1ac5b37bb","name":"In Scope - No Monetary Rewards","targets":[{"id":"dd34f2d2-9356-4a80-84eb-f36c6d38ac2b","uri":"","name":"Any Verified Dell-Controlled Endpoint (domains/IP space/etc.)\t","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"5d2da900-5ddd-4200-9857-8f2c9243e887","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eAny domain or target that is not listed in other Target Groups are in-scope for this program but not eligible for monetary rewards.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null},{"id":"c5895cd2-4c87-42be-b754-c294fd3245d2","name":"Out of Scope","targets":[{"id":"caf0c830-1e0b-43b7-aa74-5330c4013259","uri":"https://console.delltechnologies.com/ ","name":"https://console.delltechnologies.com/ ","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"896dee07-c55e-4928-9544-74bf3d72776b","sortOrder":0},"sortOrder":0,"tags":[{"id":"08e84ba6-1e84-4c11-b559-a3b3b963546f","name":"Akamai CDN","targetId":"caf0c830-1e0b-43b7-aa74-5330c4013259"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"caf0c830-1e0b-43b7-aa74-5330c4013259"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"caf0c830-1e0b-43b7-aa74-5330c4013259"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"caf0c830-1e0b-43b7-aa74-5330c4013259"}],"recentChangeFlags":null},{"id":"1b70c73e-a1d8-43ef-a7ac-27d4a5ea7198","uri":"https://console.delltechnologies.com/nav/catalog","name":"https://console.delltechnologies.com/nav/catalog","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"186713d2-1cba-4487-bea5-9abe5b21f61a","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"1b70c73e-a1d8-43ef-a7ac-27d4a5ea7198"}],"recentChangeFlags":null},{"id":"2f9ccb97-ebda-41b2-9494-5633ac627b9f","uri":"https://console.delltechnologies.com/nav/support","name":"https://console.delltechnologies.com/nav/support","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"c1efa289-1100-4bda-a515-88697b2f5502","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2f9ccb97-ebda-41b2-9494-5633ac627b9f"}],"recentChangeFlags":null},{"id":"ecb47ca5-16f8-40ba-8e14-8d83995d090a","uri":"https://console.delltechnologies.com/nav/subscriptions","name":"https://console.delltechnologies.com/nav/subscriptions","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"0b90dcc3-3281-4e6f-a1e5-45fbbc8d418d","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"ecb47ca5-16f8-40ba-8e14-8d83995d090a"}],"recentChangeFlags":null},{"id":"86d61bb7-6efc-4e33-ab49-f9f1f333ab69","uri":"","name":"educate.dell.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"48243697-226b-4336-bf11-68bd298a12bd","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"d22530fb-5e7a-4e6f-853d-6e71706721f1","uri":"","name":"console.dell.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"f4fe211e-8f95-48ec-bb03-c43640ef3f79","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"a053dcc4-e4f6-4d42-8e8f-b494a2877a7b","uri":"","name":"console-test.dell.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"49d94476-3fa9-4103-b48c-983b8bf343c0","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"10b8327c-2df8-4fd0-8a7b-75a93b48cb39","uri":"","name":"salesproductivity.dell.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"eaacc987-4aba-4b4b-8b9b-df68e243509d","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":2,"description":null,"rewardRange":null,"descriptionHtml":"\u003cul\u003e\n\u003cli\u003eXSS on the https://www.dell.com/Identity/global/* target\u003c/li\u003e\n\u003cli\u003eXSS on the https://www-poc.dell.com/Identity/* target\u003c/li\u003e\n\u003cli\u003eXSS on the https://pilot.search.dell.com/Identity/global/* target\u003c/li\u003e\n\u003cli\u003eXSS on the https://www.dell.com/sso/sm/* target\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eNote: When testing any of the application forms on the finance directory you will need stop before actually submitting the form/application. Examples of finance forms you should \u003cstrong\u003eNOT\u003c/strong\u003e submit.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.dell.com/financing/comm/dpamarcom/CreditApp\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://www.dell.com/financing/comm/dpamarcom/CreditApp\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.dell.com/Financing/Comm/PreQual?cookieUpdated=true\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://www.dell.com/Financing/Comm/PreQual?cookieUpdated=true\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"9ad4feaf-b418-49b2-9559-3c8b48f0c175","code":"dell-com","state":"in_progress","endsAt":null,"bountyId":"1410dfce-17aa-4f4d-a974-eddc99eaf050","startsAt":"2019-07-16T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/c63e/8e43/7338d03a/f1e1e5bbb52c73c333a29b25feba8aae_1024px-Dell_Logo.svg.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2019-07-16T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/dell-com","changelogs":"/engagements/dell-com/changelog","submissions":null,"announcements":"/engagements/dell-com/announcements","hallOfFame":"/engagements/dell-com/hall_of_fames","crowdstream":null},"announcementsCount":40,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/dell-com/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=dell-com\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/dell-com/engagement_subscribers","engagementChangelogsUrl":"/engagements/dell-com/changelog","publishedAt":"2024-03-11T14:09:05.800Z","engagementChangelogUrl":"/engagements/dell-com/changelog/93ea9025-907e-485e-b7a5-91709d64e741","createUserFeedbacksUrl":"/engagements/dell-com/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}