{"id":"51ac2ae2-fac7-4ebc-8605-98e314c328f4","engagementId":"eda1b70e-e51b-4d4d-af0e-40a9442746e8","data":{"brief":{"id":"268af59b-5ae8-4184-a35d-96e1cb1629ab","name":"Despegar Vulnerability Disclosure Engagement","tagline":"Despegar is Latin America’s leading travel tech firm, serving 30 million customers through its consolidated brands, including Best Day, Viajes Falabella, and Koin.","description":"\u003ch1\u003eDisclosure Policy\u003c/h1\u003e\n\n\u003cul\u003e\n\u003cli\u003eAs this is a private program, please do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from the organization.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch1\u003eProgram Rules\u003c/h1\u003e\n\n\u003cp\u003ePlease provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eSubmit one vulnerability per report unless you need to chain vulnerabilities to provide impact.\u003c/li\u003e\n\u003cli\u003eWhen duplicates occur, we only award the first report that was received (provided that it can be fully reproduced).\u003c/li\u003e\n\u003cli\u003eMultiple vulnerabilities caused by one underlying issue will be awarded one bounty.\u003c/li\u003e\n\u003cli\u003eSocial engineering (e.g., phishing, vishing, smishing) is prohibited.\u003c/li\u003e\n\u003cli\u003eMake a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. \u003c/li\u003e\n\u003cli\u003eAsk the program team \u003cstrong\u003ebefore submitting vulnerabilities on unscoped subdomains.\u003c/strong\u003e\n\u003c/li\u003e\n\u003cli\u003eOnly interact with accounts you own or with the explicit permission of the account holder.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch1\u003eTest Plan\u003c/h1\u003e\n\n\u003cp\u003eWhen testing, you can make it easier for us to identify your testing traffic against our normal data and the malicious actors out in the world. Please do the following when participating in Despegar bug bounty programs:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eProvide your IP address in the bug report. We will keep this data private and only use it to review logs related to your testing activity.\nInclude a custom User-Agent header in all your traffic. Burp and other proxies allow the easy automatic addition of headers to all outbound requests. Report to us what header you set so we can identify it easily.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eIMPORTANT: To streamline the triage process and ensure efficient handling of reports, it is now mandatory to include the specified tracking information at the beginning of your submission. This information is crucial for us to validate and reproduce reported issues effectively.\u003cbr\u003e\nReports that do not include the required tracking information will not be eligible for a bounty. Please ensure that all future submissions adhere to this guideline to qualify for bounty consideration.\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eWhen testing for a bug, please also keep in mind:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eOnly use authorized accounts so as not to inadvertently compromise the privacy of our users\u003c/li\u003e\n\u003cli\u003eWhen attempting to demonstrate root permissions with the following primitives in a vulnerable process please use the following commands:\u003c/li\u003e\n\u003cli\u003eRead: cat /proc/1/maps\u003c/li\u003e\n\u003cli\u003eWrite: touch /root/\u0026lt;your BugCrowd username\u0026gt;\u003c/li\u003e\n\u003cli\u003eExecute: id, hostname, pwd (though, technically cat and touch also prove execution)\u003c/li\u003e\n\u003cli\u003eMinimize the mayhem. Adhere to program rules at all times. Do not use automated scanners/tools - these tools include payloads that could trigger state changes or damage production systems and/or data.\u003c/li\u003e\n\u003cli\u003eBefore causing damage or potential damage: Stop, report what you've found and request additional testing permission.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch1\u003eCrafting a Report\u003c/h1\u003e\n\n\u003cp\u003eIf our security team cannot reproduce and verify an issue, a bounty cannot be awarded. To help streamline our intake process, we ask that submissions include:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDescription of the vulnerability\u003c/li\u003e\n\u003cli\u003eSteps to reproduce the reported vulnerability\u003c/li\u003e\n\u003cli\u003eProof of exploitability (e.g. screenshot, video)\u003c/li\u003e\n\u003cli\u003ePerceived impact to another user or the organization\u003c/li\u003e\n\u003cli\u003eProposed CVSSv3 Vector \u0026amp; Score (without environmental and temporal modifiers)\u003c/li\u003e\n\u003cli\u003eList of URLs and affected parameters\u003c/li\u003e\n\u003cli\u003eOther vulnerable URLs, additional payloads, Proof-of-Concept code\u003c/li\u003e\n\u003cli\u003eBrowser, OS and/or app version used during testing\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eNote: Failure to adhere to these minimum requirements may result in the loss of a reward.\u003cbr\u003e\nAll supporting evidence and other attachments must be stored only within the report you submit. Do not host any files on external services.\u003c/p\u003e\n\n\u003ch1\u003eProgram Scope\u003c/h1\u003e\n\n\u003cp\u003eVulnerabilities on a specific brand or web property should be reported to the program to which it is listed “in scope”. Please see our detailed scope list at the bottom of this page for a full list of assets that are in scope of this program. This list is subject to change without notice.\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/p\u003e\n\n\u003ch1\u003eRewards\u003c/h1\u003e\n\n\u003cp\u003eYou will be eligible for a bounty only if you are the first person to disclose an unknown issue. Qualifying bugs will be rewarded based on severity, to be determined by Despegar in its sole discretion. Rewards may range from BugCrowd Reputation Points to monetary rewards up to $3,000 USD. Awards are granted entirely at the discretion of Despegar.\u003cbr\u003e\nDespegar may pay less for vulnerabilities that require complex or over-complicated interactions or for which the impact or security risk is negligible. Rewards may be denied if there is evidence of program policy violations. A reduction in bounty is also warranted for reports that require specific browser configurations. Reports in third party software are not eligible for bounties.\u003c/p\u003e\n\n\u003cp\u003eThank you for helping keep Despegar and our users safe!\u003c/p\u003e","industryTagId":"69a00b3a-95c0-441c-b4ec-3da8c42dad0e","targetsOverview":"\u003ch2\u003eScope\u003c/h2\u003e\n\n\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Despegar not listed in the targets section is out of scope. This includes any/all subdomains not listed in Scope Groups. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eN-day/Third party 0-day Policy\u003c/h2\u003e\n\n\u003cp\u003eWhen N-Day bugs are released to the public, we will consider these as in scope after 30 days has gone by\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ee.g: N-day released on 01/01/2026, we would consider it in-scope on 01/31/2026\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eBorderline Out-of-Scope, No Bounty\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eDisclaimer: We would like to inform participants of a policy update regarding client-side vulnerabilities. Specifically, reports involving client-side attacks, such as Cross-Site Scripting (XSS) aimed at accessing session cookies lacking the HttpOnly attribute, will be evaluated based on their base severity rather than the potential for account compromise. This decision is based on a business requirement that necessitates the absence of the HttpOnly attribute for certain session cookies. While we acknowledge the potential risk. We encourage researchers to focus on other impactful security issues that align with our program's scope.\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eOut of Scope\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAny non-Despegar Applications\u003c/li\u003e\n\u003cli\u003eRate limit without security impact\u003c/li\u003e\n\u003cli\u003e\"Self\" XSS\u003c/li\u003e\n\u003cli\u003eMissing Security Best Practices\u003c/li\u003e\n\u003cli\u003eHTTP Host Header XSS\u003c/li\u003e\n\u003cli\u003eConfidential Information Leakage\u003c/li\u003e\n\u003cli\u003eClickjacking/UI Redressing\u003c/li\u003e\n\u003cli\u003eUse of known-vulnerable library (without proof of exploitability)\u003c/li\u003e\n\u003cli\u003eIntentional Open Redirects\u003c/li\u003e\n\u003cli\u003eMissing cookie flags\u003c/li\u003e\n\u003cli\u003eReflected file download\u003c/li\u003e\n\u003cli\u003eSSL/TLS Best Practices\u003c/li\u003e\n\u003cli\u003eIncomplete/Missing SPF/DKIM\u003c/li\u003e\n\u003cli\u003ePhysical attacks\u003c/li\u003e\n\u003cli\u003eSocial Engineering attacks\u003c/li\u003e\n\u003cli\u003eResults of automated scanners\u003c/li\u003e\n\u003cli\u003eLogin/Logout/Unauthenticated CSRF\u003c/li\u003e\n\u003cli\u003eAutocomplete attribute on web forms\u003c/li\u003e\n\u003cli\u003eUsing unreported vulnerabilities\u003c/li\u003e\n\u003cli\u003e\"Self\" exploitation\u003c/li\u003e\n\u003cli\u003eIssues related to networking protocols\u003c/li\u003e\n\u003cli\u003eFlash-based XSS\u003c/li\u003e\n\u003cli\u003eSoftware Version Disclosure\u003c/li\u003e\n\u003cli\u003eVerbose error pages (without proof of exploitability)\u003c/li\u003e\n\u003cli\u003eDenial of Service attacks\u003c/li\u003e\n\u003cli\u003eDespegar software that is End of Life or no longer supported\u003c/li\u003e\n\u003cli\u003eAccount/email Enumeration\u003c/li\u003e\n\u003cli\u003eMissing Security HTTP Headers (without proof of exploitability)\u003c/li\u003e\n\u003cli\u003eInternal pivoting, scanning, exploiting, or exfiltrating data\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eDo Not Report\u003c/h3\u003e\n\n\u003cp\u003eThe following issues are considered out of scope:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eThose that resolve to third-party services\u003c/li\u003e\n\u003cli\u003eIssues that do not affect the latest version of modern browsers\u003c/li\u003e\n\u003cli\u003eIssues that we are already aware of or have been previously reported\u003c/li\u003e\n\u003cli\u003eIssues that require unlikely user interaction\u003c/li\u003e\n\u003cli\u003eDisclosure of information that does not present a significant risk\u003c/li\u003e\n\u003cli\u003eCross-site Request Forgery with minimal security impact\u003c/li\u003e\n\u003cli\u003eCSV injection\u003c/li\u003e\n\u003cli\u003eGeneral best practice concerns\u003c/li\u003e\n\u003cli\u003eAll Flash-related bugs\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSpecial Situations\u003c/h2\u003e\n\n\u003cp\u003eSome situations exist that may earn partial bounties or bonuses on top of a base bounty per report. Here are a few of the most common examples.\u003c/p\u003e\n\n\u003ch3\u003eSame Bug, Different Domain\u003c/h3\u003e\n\n\u003cp\u003eSince www.despegar.com.ar and www.decolar.com share the same code base, any vulnerability identified in one domain will be considered a duplicate if the identical vulnerability is found in the same path on the other domain.\u003c/p\u003e\n\n\u003ch3\u003eSame Bug, Different Path\u003c/h3\u003e\n\n\u003cp\u003eFor each report, please allow Despegar sufficient time to patch related paths. Any reports filed separately while we are actively working to resolve the issue will be treated as a duplicate.\u003c/p\u003e\n\n\u003cp\u003eIn addition, Despegar and Decolar mobile applications share a common codebase. Therefore, if the same vulnerability is identified in both apps for the same operating system (Android or iOS), only one submission will be awarded points. The second report will be marked as a duplicate.\u003c/p\u003e\n\n\u003ch3\u003eSame Payload, Different Parameter\u003c/h3\u003e\n\n\u003cp\u003eIn some cases, submissions may be consolidated into a single submission for awarding points. For example, multiple reports of the same vulnerability across different parameters of a resource, or demonstrations of multiple attack vectors against a fundamental framework issue. We kindly ask you to consolidate reports rather than separate them.\u003cbr\u003e\nNote: Additional payloads, parameters, hosts and paths will not receive multiple bonuses.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eBreached/Stolen Credentials\u003c/h2\u003e\n\n\u003cp\u003eIf you happen to identify vulnerabilities involving data that has been exposed or leaked, such as on dark web forums or leaked credential sites, you can report them through this engagement. Please note that compensation varies depending on the nature of the credentials involved: if the leaked credentials belong to a Despegar employee and are applicable to internal or third-party platforms posing a security risk, they will be evaluated and, following an impact review, may be eligible for a bounty payment. However, if the credentials belong to customers, they will not be eligible for any compensation. This policy helps maintain the highest standard of operational confidentiality, integrity, and compliance.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy;\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/login\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"f3931c1d-5d06-4c0a-996a-c4254c258ebd","name":"In Scope","targets":[{"id":"f7c3859b-c9f5-41c3-901d-84ed07f72d0f","uri":"https://www.depegar.com.ar","name":"Despegar","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"443604c5-eb28-47e8-b543-499c6a0e0d0e","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"f7c3859b-c9f5-41c3-901d-84ed07f72d0f"},{"id":"5a702681-f59c-463c-b266-f9e22a1e1d8a","name":"Scala","targetId":"f7c3859b-c9f5-41c3-901d-84ed07f72d0f"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"f7c3859b-c9f5-41c3-901d-84ed07f72d0f"}],"recentChangeFlags":null},{"id":"070fca46-db81-4dbc-8c40-335db5383adf","uri":"https://www.decolar.com","name":"Decolar","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"de54e903-4226-4d56-bad9-122c496ec881","sortOrder":1},"sortOrder":1,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"070fca46-db81-4dbc-8c40-335db5383adf"},{"id":"5a702681-f59c-463c-b266-f9e22a1e1d8a","name":"Scala","targetId":"070fca46-db81-4dbc-8c40-335db5383adf"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"070fca46-db81-4dbc-8c40-335db5383adf"}],"recentChangeFlags":null},{"id":"70233e3d-a909-49c8-a381-e6bb61a604c9","uri":"https://apps.apple.com/us/app/despegar-vuelos-y-hoteles/id511479725","name":"Despegar iOS App","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"160c30f5-7f3a-4503-a40d-5a7028bcbf79","sortOrder":2},"sortOrder":2,"tags":[{"id":"a47bcaa8-a080-4539-b4ca-e699e72d2023","name":"Swift","targetId":"70233e3d-a909-49c8-a381-e6bb61a604c9"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"70233e3d-a909-49c8-a381-e6bb61a604c9"}],"recentChangeFlags":null},{"id":"12003930-6089-4674-b96d-fe17862ffc9f","uri":"https://play.google.com/store/apps/details?id=com.gm.despegar\u0026hl=en_US","name":"Despegar Android App","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"596c5146-8761-488c-935b-a3c334cea6ad","sortOrder":3},"sortOrder":3,"tags":[{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"12003930-6089-4674-b96d-fe17862ffc9f"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"12003930-6089-4674-b96d-fe17862ffc9f"}],"recentChangeFlags":null},{"id":"5bd3033f-40f1-467e-9448-1c1fb3dd194a","uri":"https://apps.apple.com/br/app/decolar-voos-e-hot%C3%A9is/id583990782","name":"Decolar iOS App","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"17a0ba79-6f57-48c7-966d-21178018dce7","sortOrder":4},"sortOrder":4,"tags":[{"id":"a47bcaa8-a080-4539-b4ca-e699e72d2023","name":"Swift","targetId":"5bd3033f-40f1-467e-9448-1c1fb3dd194a"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"5bd3033f-40f1-467e-9448-1c1fb3dd194a"}],"recentChangeFlags":null},{"id":"b152c837-c935-405f-85c5-f59c158a4418","uri":"https://play.google.com/store/apps/details?id=com.gm.decolar","name":"Decolar Android App","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"19ca2755-bd13-49ca-b31b-da06e33ff7a9","sortOrder":5},"sortOrder":5,"tags":[{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"b152c837-c935-405f-85c5-f59c158a4418"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"b152c837-c935-405f-85c5-f59c158a4418"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"eda1b70e-e51b-4d4d-af0e-40a9442746e8","code":"despegar-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"c7ef49ad-2636-4fe9-b59f-8e7cff53ea0b","startsAt":"2026-04-28T12:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Tourism","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/1260/6edc/b5ba81a6/0ee6b61b81413ecdebfe7dba0f54b313_despegarcom_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2026-04-28T12:00:00.053Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/despegar-vdp-pro","changelogs":"/engagements/despegar-vdp-pro/changelog","submissions":null,"announcements":"/engagements/despegar-vdp-pro/announcements","hallOfFame":"/engagements/despegar-vdp-pro/hall_of_fames","crowdstream":"/engagements/despegar-vdp-pro/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/despegar-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=despegar-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/despegar-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/despegar-vdp-pro/changelog","publishedAt":"2026-04-28T12:00:00.093Z","engagementChangelogUrl":"/engagements/despegar-vdp-pro/changelog/51ac2ae2-fac7-4ebc-8605-98e314c328f4","createUserFeedbacksUrl":"/engagements/despegar-vdp-pro/feedbacks","engagementCrowdstreamUrl":"/engagements/despegar-vdp-pro/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}