{"id":"396b4476-b29c-4266-88f1-b9c29d6e96ba","engagementId":"8db0a62d-4c35-4184-aa3f-37f216c5a667","data":{"brief":{"id":"8439df58-1cca-41a7-bfc6-e61b72ceab2d","name":"Eurofins Vulnerability Disclosure Engagement","tagline":"Testing For Life","description":"\u003cp\u003eSince 1987, Eurofins has grown from one laboratory in Nantes, France to over 65,000 staff across a network of independent companies in 59 countries, operating over 950 laboratories.\u003c/p\u003e\n\n\u003cp\u003ePerforming over 450 million tests every year, Eurofins offers a portfolio of over 200,000 analytical methods to evaluate the safety, identity, composition, authenticity, origin, traceability and purity of biological substances and products, as well as providing innovative clinical diagnostic testing services, as one of the leading global emerging players in specialised clinical diagnostics testing.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRatings\u003c/h2\u003e\n\n\u003cp\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/p\u003e\n\n\u003ch2\u003eLegal Notice\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eBy submitting your report, you grant Eurofins, its subsidiaries, affiliates, and contractors a perpetual, worldwide, exclusive, irrevocable, no charge, transferrable, sublicensable (through multiple tiers) and non-exclusive license to copy, distribute, display, perform, transmit, publish, or otherwise use the report or any part thereof.\u003c/li\u003e\n\u003cli\u003eYou hereby represent and warrant that the report submission is original to you and you own all rights, title, and interest in and to the report submission. Further, you hereby waive all other claims of any nature, including express contract, implied-in-fact contract, or quasi-contract, arising out of any disclosure of the report submission to Eurofins.\u003c/li\u003e\n\u003cli\u003eYou understand that nothing in this Policy shall be deemed to constitute the grant to you of any license or other right to or in respect of any Eurofins or third-party product, service, patent, trademark, trade secret, or other intellectual property.\u003c/li\u003e\n\u003cli\u003eBy submitting your report, you provide Eurofins with your consent to process personal data contained in the report (if any) in accordance with the Eurofins Privacy Policy.\u003c/li\u003e\n\u003cli\u003eAny information you receive or collect about Eurofins or any Eurofins user or customer through the this VDP (“Confidential Information”) must be kept confidential and only used in connection with the VDP. You may not use, disclose or distribute any such Confidential Information, including, but not limited to, any information regarding your Submission and information you obtain when researching the Eurofins scope, except upon receiving explicit written authorization from Eurofins.\u003c/li\u003e\n\u003c/ul\u003e","industryTagId":"294ffef8-c25d-45d6-837d-1f76bbd777cf","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Eurofins not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Eurofins, you can report it to this engagement. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eEngagement Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWe do not accept reports that contain low-effort or AI-generated content. Submissions must demonstrate original analysis, clear understanding of the issue, and actionable detail. Reports lacking meaningful human input will be rejected\u003c/li\u003e\n\u003cli\u003eResearchers must throttle all testing activity to avoid degrading service availability, triggering automated defenses, or negatively impacting other users. Excessive request rates, high-volume scanning, denial-of-service techniques, or other disruptive testing methods are prohibited\u003c/li\u003e\n\u003cli\u003ePotential post-exploitation scenarios: If you believe you've identified a vulnerability that may lead to post-exploitation activity including modification or destruction of data please stop testing and submit your finding. We will work with you to evaluate the vulnerability and award you accordingly for the final impact and severity\u003c/li\u003e\n\u003cli\u003eYou are testing on production. Behavior that compromises the stability and integrity of the target(s) is out of scope.\n\n\u003cul\u003e\n\u003cli\u003eFor example, do not target other users' data (use one of your other sets of credentials), delete/remove/edit parts of the site, engage any sort of DoS attack, and/or compromise any target's ability to function for other users. If you believe that you have found a vulnerability of this nature, please stop further testing and report it\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eReporting\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities discovered on multiple paths, endpoints, parameters will be treated as duplicates. This includes findings across different environments (e.g., development, staging, production) unless the impact or exploitation method is materially different. Please submit only one report\u003c/li\u003e\n\u003cli\u003eReports must contain the role used for testing, a clear explanation of the issue and the security impact along with detailed steps to reproduce it. If the issue cannot be reliably reproduced based on your report, it may be considered ineligible for a reward\u003c/li\u003e\n\u003cli\u003eReports based only on automated tool/scanner results or which describe theoretical attack vectors without proof of exploitability will not be accepted\u003c/li\u003e\n\u003cli\u003eRemediation Suggestion: While not mandatory, we encourage researchers to suggest a fix to assist our developers with remediation\u003c/li\u003e\n\u003cli\u003eDo not submit more than one vulnerability per report. In cases where demonstrating impact requires chaining multiple vulnerabilities together, those can be included in the same report as long as the linkage is clearly explained\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess\u003c/h2\u003e\n\n\u003cp\u003eAll targets within scope are publicly accessible.\u003c/p\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003e_There are no credentials provided for this engagement. Hackers should mimic external threat. _\u003c/p\u003e\n\n\u003cp\u003eWhere account creation is possible, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003eOut of Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eTesting third-party applications, websites, or services that integrate with or link to Eurofins properties\u003c/li\u003e\n\u003cli\u003eMissing http security headers which do not lead to a vulnerability\u003c/li\u003e\n\u003cli\u003eForms missing CSRF tokens (we require evidence of actual CSRF vulnerability)\u003c/li\u003e\n\u003cli\u003eLogin/logout CSRF or CSRF on non-sensitive actions (e.g. adding products to shopping carts without a direct impact)\u003c/li\u003e\n\u003cli\u003ePassword and account recovery policies, such as reset link expiration or password complexity.\u003c/li\u003e\n\u003cli\u003eClickjacking without an impact\u003c/li\u003e\n\u003cli\u003eContent spoofing / reflection / injection (on 404 page, search result page etc.) unless executes code\u003c/li\u003e\n\u003cli\u003eKnown-vulnerable library (without evidence of exploitability)\u003c/li\u003e\n\u003cli\u003eCertain reports of spam\u003c/li\u003e\n\u003cli\u003eMissing best practices in Content Security Policy\u003c/li\u003e\n\u003cli\u003eMissing HttpOnly or Secure flags on cookies\u003c/li\u003e\n\u003cli\u003eMissing email best practices (Invalid, incomplete, or missing SPF/DKIM/DMARC records, etc.)\u003c/li\u003e\n\u003cli\u003eLow impact host header issues\u003c/li\u003e\n\u003cli\u003eHard to exploit SSL/TLS protocol vulnerabilities, Missing best practices in SSL/TLS configuration\u003c/li\u003e\n\u003cli\u003eRate limiting or brute-force issues on non-authentication endpoints or authentication endpoints which are secured by additional measures (e.g. MFA)\u003c/li\u003e\n\u003cli\u003eSoftware version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application, or server errors)\u003c/li\u003e\n\u003cli\u003eTabnabbing\u003c/li\u003e\n\u003cli\u003eOpen redirect - unless an additional security impact can be demonstrated\u003c/li\u003e\n\u003cli\u003eOpen ports which do not lead directly to a vulnerability\u003c/li\u003e\n\u003cli\u003eReports from automated tools or scans without a working Proof of Concept\u003c/li\u003e\n\u003cli\u003eExposed credentials that are either no longer valid, or do not pose a risk to an in scope asset\u003c/li\u003e\n\u003cli\u003eVulnerabilities only affecting users of outdated or unpatched browsers and platforms\u003c/li\u003e\n\u003cli\u003eEmail enumeration\u003c/li\u003e\n\u003cli\u003eCookie and logout policies\u003c/li\u003e\n\u003cli\u003eComma Separated Values (CSV) injection without demonstrating a vulnerability\u003c/li\u003e\n\u003cli\u003eVulnerabilities which require a jailbroken device\u003c/li\u003e\n\u003cli\u003eAPI keys found in our mobile applications\u003c/li\u003e\n\u003cli\u003eAttacks requiring physical access to a user's device or Attacks requiring MITM\u003c/li\u003e\n\u003cli\u003ePhysical security of Eurofins facilities, employees, equipment, etc\u003c/li\u003e\n\u003cli\u003eTests in a manner that would corrupt the operation of Eurofins solutions\u003c/li\u003e\n\u003cli\u003eIssues that require unlikely user interaction\u003c/li\u003e\n\u003cli\u003eSocial engineering (e.g. phishing, vishing, smishing)\u003c/li\u003e\n\u003cli\u003ePhysical attacks\u003c/li\u003e\n\u003cli\u003eAny testing that could harm our services or customers, including launching any large-scale automated attacks (e.g. denial-of-service attacks (DDoS)), Spam, pyramid schemes, or deployment or use any other malicious software or technology\u003c/li\u003e\n\u003cli\u003eIntentional conduct that deletes or alters user-generated data; impairs, disrupts, or disables systems; or renders data inaccessible\u003c/li\u003e\n\u003cli\u003eViolation of any laws, including Data Protection Laws, other officially binding rules or regulatory provisions, courts of law and administrative court judgements, such as codes of practice, public authority decisions, specifically but not limited to all competition, privacy, personal data protection and information security laws\u003c/li\u003e\n\u003cli\u003eAccessing, copying, modification, deletion, publishing or otherwise disclosing as well as making any other use or making advantage of any Eurofins information, including personal data of any kind.\u003c/li\u003e\n\u003cli\u003eIncluding any Personal Data in the disclosed vulnerability report\u003c/li\u003e\n\u003cli\u003ePublic disclosure of any Eurofins Confidential Information, specifically the details of the vulnerability, indicator of vulnerability, or the content of information rendered available by a vulnerability, except upon receiving prior explicit written authorization from Eurofins\u003c/li\u003e\n\u003cli\u003eCSRF on forms that are available to anonymous users\u003c/li\u003e\n\u003cli\u003eDisclosure of known public files or directories (e.g. robots.txt)\u003c/li\u003e\n\u003cli\u003eLack of Secure/HTTPOnly flags on non-sensitive cookies\u003c/li\u003e\n\u003cli\u003eLogout Cross Site Request Forgery\u003c/li\u003e\n\u003cli\u003eVulnerabilities only affecting users who are using outdated or unpatched browsers and platforms\u003c/li\u003e\n\u003cli\u003eTesting that would result in sending spam or other unsolicited messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eP5 vulnerabilities\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003cp\u003e\u003cstrong\u003eDefinitions\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e“Eurofins” or “Eurofins Group” means any entity that is under direct or indirect control of Eurofins Scientific S.E.\u003c/li\u003e\n\u003cli\u003e“VDP” means Vulnerability Disclosure Program\u003c/li\u003e\n\u003cli\u003e“Data Protection Laws” mean any relevant international or national binding laws regulating the use and protection of Personal Data, including but not limited to the GDPR, CCPA, UK Data Protection Act 2018 (and any replacement law that may be issued by the United Kingdom in relation to the UK Brexit), as well as related guidance, instructions or opinions and judgments issued by the competent public authorities or courts of law.\u003c/li\u003e\n\u003cli\u003e“The GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).\u003c/li\u003e\n\u003cli\u003e“Personal Data” is any information that identifies, relates to, describes, is reasonably capable of being associated with an identified or identifiable individual (natural person), or could reasonably be linked, directly or indirectly with a particular individual (or household in certain jurisdictions).\u003c/li\u003e\n\u003cli\u003eEurofins Confidential Information means any confidential or proprietary business or technical information about Eurofins disclosed by it or made available in connection with this VDP, whether disclosed in written, electronic or visual form, which is identified as confidential at the time of disclosure or should reasonably be understood to be confidential given the nature of the information and the circumstances surrounding the disclosure, including without limitation business, operations, finances, technologies, products and services, pricing, personnel, customer and suppliers, including the this Platform and the content of the report.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eThank you for helping keep Eurofins and our customers safe!\u003c/strong\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":false,"additionalInformation":""},"scope":[{"id":"14141c8c-c006-4b23-b377-13d505308697","name":"In Scope","targets":[{"id":"50ab5482-2b70-4c14-b5fc-3c3ef434c8d8","uri":"","name":"All Eurofins Assets","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a8e11ad7-aafa-4077-adee-f5805ba6c7b3","sortOrder":0},"sortOrder":0,"tags":[{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"50ab5482-2b70-4c14-b5fc-3c3ef434c8d8"},{"id":"53917c1d-52c8-41f3-86f5-166e787ece8f","name":"Select2","targetId":"50ab5482-2b70-4c14-b5fc-3c3ef434c8d8"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"50ab5482-2b70-4c14-b5fc-3c3ef434c8d8"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"8db0a62d-4c35-4184-aa3f-37f216c5a667","code":"eurofins-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"5fa5e87c-caec-4208-8789-1b11fc37a331","startsAt":"2026-06-23T18:00:00Z"},"vrtScopeRules":[{"id":"22a2505c-bfe1-49d8-9254-4128c8d4d46d","notes":"","targets":[],"vrtIds":{"categories":[{"id":"application_level_denial_of_service_dos","version":"1.18"},{"id":"cross_site_request_forgery_csrf.action_specific.logout","version":"1.18"},{"id":"cross_site_scripting_xss.ie_only","version":"1.18"},{"id":"physical_security_issues","version":"1.18"},{"id":"other","version":"1.18"}]},"allTargets":true,"targetGroups":[],"exclusionType":"out_of_scope"}],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Science","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/5175/88ce/5a05a2d0/cefddc92ae04688f543e0b45ada2005b_eurofins_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":false,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2026-06-23T18:00:00.245Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/eurofins-vdp-pro","changelogs":"/engagements/eurofins-vdp-pro/changelog","submissions":null,"announcements":"/engagements/eurofins-vdp-pro/announcements","hallOfFame":"/engagements/eurofins-vdp-pro/hall_of_fames","crowdstream":null},"announcementsCount":0,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/eurofins-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=eurofins-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/eurofins-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/eurofins-vdp-pro/changelog","publishedAt":"2026-06-23T18:00:00.278Z","engagementChangelogUrl":"/engagements/eurofins-vdp-pro/changelog/396b4476-b29c-4266-88f1-b9c29d6e96ba","createUserFeedbacksUrl":"/engagements/eurofins-vdp-pro/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[{"id":"22a2505c-bfe1-49d8-9254-4128c8d4d46d","vrt_ids":{"categories":[{"id":"application_level_denial_of_service_dos","lineage":"Application-Level Denial-of-Service (DoS)","version":"1.18"},{"id":"cross_site_request_forgery_csrf.action_specific.logout","lineage":"Cross-Site Request Forgery (CSRF) \u003e Action-Specific \u003e Logout","version":"1.18"},{"id":"cross_site_scripting_xss.ie_only","lineage":"Cross-Site Scripting (XSS) \u003e IE-Only","version":"1.18"},{"id":"physical_security_issues","lineage":"Physical Security Issues","version":"1.18"},{"id":"other","lineage":"Other","version":"1.18"}]},"targets":[],"target_groups":[],"exclusion_type":"out_of_scope","notes":"","all_targets":true}]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}