{"id":"9d02978a-c82f-4cbd-9af6-34d75b580305","engagementId":"bc0ee98a-f3c3-48b5-bc13-eaec9f49723e","data":{"brief":{"id":"a2d5aa19-656a-4dac-9cab-07bfaae0b7e8","name":"eToro Managed Bug Bounty Engagement","tagline":"The world's leading social Investment network","description":"\u003cp\u003eeToro is a global social investment and multi-asset brokerage company that pioneered the concept of \"social trading.\" Operating at the intersection of Fintech and WealthTech, eToro provides a user-friendly platform where retail investors can trade a diverse range of assets, including stocks, cryptocurrencies, ETFs, commodities, and currencies.\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"6bf30795-7930-4c2b-bb79-d2c4f15f7740","targetsOverview":"\u003ch2\u003eScope\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of eToro not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to eToro, you can report it to this engagement. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch2\u003eOut-of-Scope Exceptions \u0026amp; Discretionary Policy\u003c/h2\u003e\n\n\u003cp\u003eWhile we maintain a defined scope, we recognize that security risks can exist in unexpected places. We will consider accepting submissions for assets not technically listed as in scope if they meet the following criteria:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eOwnership \u0026amp; Impact\u003c/strong\u003e: The asset must be owned or managed by eToro (including assets managed by our employees). To be considered, the vulnerability must demonstrate a clear, credible impact on eToro’s infrastructure, its employees, or its customers.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eActionability\u003c/strong\u003e: As a rule of thumb, if the issue carries a direct impact and the remediation must be performed by eToro employees, the submission will likely be accepted. \u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eReward Structure\u003c/strong\u003e:  Base rewards for out-of-scope submissions are typically 50% lower than their in-scope counterparts.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eImpact is the deterministic factor\u003c/strong\u003e: If a submission demonstrates significant exploitability and high impact, we will frequently apply a discretionary bonus to compensate for the lower base reward.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eWe ask that:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou provide us reasonable time to investigate and mitigate all reports. We’ll try to keep you informed about our progress throughout the process but we are not obligated to.\u003c/li\u003e\n\u003cli\u003eAny finding provided by you shall be confidential and cannot be disclosed to third parties (even resolved ones) without our express consent. violations of this section could disqualify you from the program.\u003c/li\u003e\n\u003cli\u003eYou do not interact with an individual account (which includes modifying or accessing data from the account) without the owner’s written consent. \u003c/li\u003e\n\u003cli\u003eYou make a good faith effort to avoid privacy violations and disruptions to others, including (but not limited to) unauthorized access to or destruction of data and interruption or degradation of our services.\u003c/li\u003e\n\u003cli\u003eYou refrain from exploiting a security issue you discover for any reason (this includes demonstrating additional risk, such as attempted compromise of sensitive company data or probing for additional issues.)\u003c/li\u003e\n\u003cli\u003eYou do not intentionally violate any other applicable laws or regulations, including (but not limited to) laws and regulations prohibiting unauthorized access to data.\u003c/li\u003e\n\u003cli\u003eFor the purposes of this policy, you are not authorized to access user data or company data, including (but not limited to) personally identifiable information and data relating to an identified or identifiable natural person.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eBug Bounty Program Terms:\u003c/h3\u003e\n\n\u003cp\u003eWe recognize security researchers help us keep people safe by reporting vulnerabilities in our services.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eThe following details must be recorded by the hacker prior to any testing and may be requested by eToro: IP Address, User-agent, Usernames used in the platform (when used).\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003eAdhere to our policy.\u003c/li\u003e\n\u003cli\u003eReport a security bug: that is, identify a vulnerability in our services or infrastructure which creates a security or privacy risk (note that eToro ultimately determines the risk of an issue and that many software bugs are not security issues.)\u003c/li\u003e\n\u003cli\u003eIf you inadvertently cause a privacy violation or disruption (such as accessing account data, service configurations, or other confidential information) while investigating an issue, you must disclose this in your report.\u003c/li\u003e\n\u003cli\u003eDo not interact with other accounts without written consent.\u003c/li\u003e\n\u003cli\u003eYour activities must not violate any law, or disrupt or compromise any of eToro data.\u003c/li\u003e\n\u003cli\u003eWe highly appreciate including steps to remediation in your report.\u003c/li\u003e\n\u003cli\u003eWe reserve the right to publish reports (and accompanying updates).\u003c/li\u003e\n\u003cli\u003eBy making a submission, you represent and warrant that the report is original to you.\u003c/li\u003e\n\u003cli\u003eWe reserve the right to modify the eToro Bug Bounty Program terms and conditions at any time.\u003c/li\u003e\n\u003cli\u003eUsage of automated tooling in order to send a massive amount of requests including Stress Testing is strictly forbidden and could result in being removed from the program.\u003c/li\u003e\n\u003cli\u003eFile upload vulnerabilities are in scope, however, please refrain from creating large request volumes (over 75 files).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eCredentials\u003c/h3\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e. You may register for accounts \u003ca href=\"https://www.etoro.com/accounts/sign-up\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch3\u003eAccess/Traffic Identification\u003c/h3\u003e\n\n\u003cp\u003ePlease add the following header to your HTTP traffic to prevent interruptions and verify non-malicious behavior:\u003cbr\u003e\n\u003ccode\u003eX-Bug-Bounty:\u0026lt;bugcrowdusername\u0026gt;\u003c/code\u003e\u003c/p\u003e\n\n\u003ch2\u003eExcluded Submission Types\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eP5 vulnerabilities\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvailability/volumetric testing e.g.:\n\n\u003cul\u003e\n\u003cli\u003eDoS/DDoS/Network DoS\u003c/li\u003e\n\u003cli\u003eRate limiting bypass attempts\u003c/li\u003e\n\u003cli\u003eEmail bombing flooding\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eN-day/Third party 0-day Policy\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen N-Day bugs are released to the public, we will consider these as in scope after 30 days has gone by\n\n\u003cul\u003e\n\u003cli\u003ee.g: N-day released on 01/01/2025, we would consider it in-scope on 01/30/2025\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut of Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eInteracting or manipulate other stakeholders and their associated accounts including:\n\n\u003cul\u003e\n\u003cli\u003eSocial engineering attacks\u003c/li\u003e\n\u003cli\u003ePhishing attacks\u003c/li\u003e\n\u003cli\u003ePhysical attacks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eThird party providers and services\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePotential post-exploitation scenarios\u003c/strong\u003e: If you believe you've identified a vulnerability that may lead to post-exploitation activity including modification or destruction of data please stop testing and submit your finding. We will work with you to evaluate the vulnerability and award you accordingly for the final impact and severity.\u003c/li\u003e\n\u003cli\u003eClickjacking/CORS related (We are using Cordova framework on mobile platforms which sadly requires broken CORS).\u003c/li\u003e\n\u003cli\u003eAny vulnerability regarding Facebook SDK on mobile.\u003c/li\u003e\n\u003cli\u003eWordPress vulnerabilities with low/medium severity.\u003c/li\u003e\n\u003cli\u003eVulnerabilities on pages with no sensitive actions or information.\u003c/li\u003e\n\u003cli\u003eUnauthenticated/logout/login CSRF.\u003c/li\u003e\n\u003cli\u003eLack of rate-limit.\u003c/li\u003e\n\u003cli\u003eUsername/email enumeration.\u003c/li\u003e\n\u003cli\u003ePassword complexity requirements, account/email enumeration, or any report that discusses how you can learn whether a given username or email address has an eToro account.\u003c/li\u003e\n\u003cli\u003eAttacks requiring MITM or physical access to a user's device.\u003c/li\u003e\n\u003cli\u003ePreviously known vulnerable libraries without a working Proof of Concept.\u003c/li\u003e\n\u003cli\u003eCSV injection without demonstrating a vulnerability.\u003c/li\u003e\n\u003cli\u003eMissing best practices in SSL/TLS/Ciphers configuration.\u003c/li\u003e\n\u003cli\u003eAny activity that could lead to the disruption of our service (DoS).\u003c/li\u003e\n\u003cli\u003eSelf-XSS, or XSS that does not affect authenticated users.\u003c/li\u003e\n\u003cli\u003eReports involving leaked credentials from third-party sites.\u003c/li\u003e\n\u003cli\u003eIssues that require the user to install a malicious third-party app on mobile.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eVulnerabilities that will be triaged as Low [with a minimum bounty] (until further notice):\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eSubdomain takeover\u003c/li\u003e\n\u003cli\u003eMissing SPF/DKIM/DMARC records on any of our domains.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eStolen/Breached Credentials\u003c/h2\u003e\n\n\u003cp\u003eReports involving leaked eToro employee credentials may be eligible for rewards provided they are novel, valid, and sourced ethically. To qualify:\u003c/p\u003e\n\n\u003col\u003e\n\u003cli\u003eThe leak must be previously unknown to eToro.\u003c/li\u003e\n\u003cli\u003eThe credentials must be confirmed as active and valid for login by our team.\u003c/li\u003e\n\u003cli\u003eThe data must originate from a non-paid source (we will not fund illegal data-selling platforms).\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003cp\u003eReports that do not meet these criteria, or involve non-employee data, remain eligible for points-only compensation.\u003c/p\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"ecf0d1d6-4062-4ded-9f30-33e9b4700a07","name":"In Scope","targets":[{"id":"41226c89-398a-45f4-849f-5bebd2e2d99b","uri":"https://*.etoro.com","name":"*.etoro.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"8e366aa2-47c9-4c42-bef5-033e2474b06a","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"7a60aac6-1437-445b-83a9-8ef8840b6867","uri":"https://io.getdelta.ios","name":"io.getdelta.ios","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"11979826-31c6-438f-95d6-c45ce9b1ecd8","sortOrder":1},"sortOrder":1,"tags":[{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"7a60aac6-1437-445b-83a9-8ef8840b6867"}],"recentChangeFlags":null},{"id":"96c051d8-b320-4b1d-b368-586dc384f3a5","uri":"https://io.getdelta.android","name":"io.getdelta.android","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f10dacc4-3307-4d2e-af9b-0f557ec8f6ff","sortOrder":2},"sortOrder":2,"tags":[{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"96c051d8-b320-4b1d-b368-586dc384f3a5"}],"recentChangeFlags":null},{"id":"dbedf826-fa03-4c1f-b3a5-be54f1720282","uri":"https://etoropartners.com","name":"etoropartners.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"31b19227-a563-4797-9eb5-b7d6d61b1665","sortOrder":3},"sortOrder":3,"tags":[{"id":"70f8fc74-f147-45d5-8f56-9bff2f555bd7","name":".NET","targetId":"dbedf826-fa03-4c1f-b3a5-be54f1720282"},{"id":"b6333057-ce1f-4205-bcb6-ce56be83543b","name":"Microsoft IIS","targetId":"dbedf826-fa03-4c1f-b3a5-be54f1720282"}],"recentChangeFlags":null},{"id":"0f39071b-e52f-4b95-b030-2afd4ba4fe04","uri":"https://delta.app","name":"delta.app","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"579ef477-2552-498e-a0d9-42d02926a3b4","sortOrder":4},"sortOrder":4,"tags":[{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"0f39071b-e52f-4b95-b030-2afd4ba4fe04"}],"recentChangeFlags":null},{"id":"0d9561f1-0072-4282-ad60-d80657fee86c","uri":"https://com.etoro.wallet","name":"com.etoro.wallet","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c52bbdf5-16d8-466d-be81-1d9b1ea82ed9","sortOrder":5},"sortOrder":5,"tags":[{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"0d9561f1-0072-4282-ad60-d80657fee86c"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"0d9561f1-0072-4282-ad60-d80657fee86c"}],"recentChangeFlags":null},{"id":"d40b8d5e-db52-4a21-b9e7-32423a901abf","uri":"https://com.etoro.openbook","name":"com.etoro.openbook","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"793f5557-e4a6-4507-aa4e-c7e2dfe0971f","sortOrder":6},"sortOrder":6,"tags":[{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"d40b8d5e-db52-4a21-b9e7-32423a901abf"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"d40b8d5e-db52-4a21-b9e7-32423a901abf"}],"recentChangeFlags":null},{"id":"c04f28d8-79cb-4c64-bfd2-9c42b5b18462","uri":"https://etorox.com","name":"etorox.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"4b8f0fe7-ffe5-4a8f-b974-3b6e39d806a8","sortOrder":7},"sortOrder":7,"tags":[{"id":"70f8fc74-f147-45d5-8f56-9bff2f555bd7","name":".NET","targetId":"c04f28d8-79cb-4c64-bfd2-9c42b5b18462"},{"id":"b6333057-ce1f-4205-bcb6-ce56be83543b","name":"Microsoft IIS","targetId":"c04f28d8-79cb-4c64-bfd2-9c42b5b18462"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"f21b50cd-9a4c-48a0-a0a7-3f293cace045","p1MaxCents":1500000,"p1MinCents":600000,"p2MaxCents":600000,"p2MinCents":150000,"p3MaxCents":100000,"p3MinCents":50000,"p4MaxCents":50000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eTarget Information:\u003c/h2\u003e\n\n\u003cp\u003eetoro.com is a platform that provides a user-friendly platform where retail investors can trade a diverse range of assets, including stocks, cryptocurrencies, ETFs, commodities, and currencies.\u003c/p\u003e\n\n\u003cp\u003ePlease find the documentation here - https://help.etoro.com\u003c/p\u003e\n\n\u003ch2\u003eOut-of-Scope Exceptions \u0026amp; Discretionary Policy\u003c/h2\u003e\n\n\u003cp\u003eWhile we maintain a defined scope, we recognize that security risks can exist in unexpected places. We will consider accepting submissions for assets not technically listed as in scope if they meet the following criteria:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eOwnership \u0026amp; Impact\u003c/strong\u003e: The asset must be owned or managed by eToro (including assets managed by our employees). To be considered, the vulnerability must demonstrate a clear, credible impact on eToro’s infrastructure, its employees, or its customers.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eActionability\u003c/strong\u003e: As a rule of thumb, if the issue carries a direct impact and the remediation must be performed by eToro employees, the submission will likely be accepted. \u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eReward Structure\u003c/strong\u003e:  Base rewards for out-of-scope submissions are typically 50% lower than their in-scope counterparts.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eImpact is the deterministic factor\u003c/strong\u003e: If a submission demonstrates significant exploitability and high impact, we will frequently apply a discretionary bonus to compensate for the lower base reward.\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":6000,"max":15000},"2":{"min":1500,"max":6000},"3":{"min":500,"max":1000},"4":{"min":100,"max":500},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"bc0ee98a-f3c3-48b5-bc13-eaec9f49723e","code":"etoro-mbb-og","state":"in_progress","endsAt":null,"bountyId":"6b966c65-fa9b-456e-974f-5fbbcd7947ac","startsAt":"2026-03-03T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Finance","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/19cf/114a/338edf8d/333bd4940640af66ef6757487fcf0da1_1662966768718.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2026-03-03T18:00:00.411Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/etoro-mbb-og","changelogs":"/engagements/etoro-mbb-og/changelog","submissions":null,"announcements":"/engagements/etoro-mbb-og/announcements","hallOfFame":"/engagements/etoro-mbb-og/hall_of_fames","crowdstream":"/engagements/etoro-mbb-og/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/etoro-mbb-og/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=etoro-mbb-og\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/etoro-mbb-og/engagement_subscribers","engagementChangelogsUrl":"/engagements/etoro-mbb-og/changelog","publishedAt":"2026-06-05T15:48:33.393Z","engagementChangelogUrl":"/engagements/etoro-mbb-og/changelog/9d02978a-c82f-4cbd-9af6-34d75b580305","createUserFeedbacksUrl":"/engagements/etoro-mbb-og/feedbacks","engagementCrowdstreamUrl":"/engagements/etoro-mbb-og/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}