{"id":"fe9726ec-9264-49e8-9fbf-2bb7e7439542","engagementId":"216c3bba-9e23-4e46-a21c-50bbd1901398","data":{"brief":{"id":"7d76b470-8486-4b62-a81a-64a99bbd2009","name":"Felix Health Managed Bug Bounty Engagement","tagline":"Felix aims to provide easier access to lifestyle healthcare, introducing a new model of care to change behaviors, attitudes, and conventions around personal health.","description":"\u003cp\u003eFelix Health (“Felix”) is an integrated healthcare platform operating in Canada. Patients using the Felix platform can get treatment for specific classes of conditions in consultation with licensed healthcare practitioners.\u003c/p\u003e\n\n\u003cp\u003eThe care provided on the Felix platform is provided by nurse practitioners (“NPs”) or Doctors of Medicine (“MDs”), collectively “HCPs”. They are duly licensed in their region(s) of practice. These individuals practice independently with the assistance of the platform’s operations and technology teams to provide safe, evidence-based healthcare. When requested, Felix can ship medication directly to patients on a regular cadence.\u003c/p\u003e\n\n\u003cp\u003eNo technology is perfect and Felix Health believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our assets. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"50214b57-2dde-40fd-ae5a-6680372523d4","targetsOverview":"\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Felix Health not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Felix Health, you can report it to this program. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003eYou have been provisioned a pseudo-random @bugcrowdninja email that has been pre-provisioned to an account with access to the app - which, after accepting the program invite, will route all incoming traffic to the email associated with your Bugcrowd account. An invite to the application has been sent to each of these emails in advance and will be auto-forwarded upon accepting your invite to the program.\u003c/p\u003e\n\n\u003cp\u003eYou must use the following request header:\u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eIdentifier\u003c/th\u003e\n\u003cth\u003eHeader\u003c/th\u003e\n\u003cth\u003eExample\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eUsername\u003c/td\u003e\n\u003ctd\u003eX-Bug-Bounty: Bugcrowd-\u0026lt;Username\u0026gt;\u003c/td\u003e\n\u003ctd\u003eX-Bug-Bounty: Bugcrowd-proresearcher\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAbout the Bug Bounty Program\u003c/h2\u003e\n\n\u003cp\u003eThe focus of our bug bounty program will be the patient experience at Felix. The patient experience is made of two pieces: quiz and patient dashboard.\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eQuiz\u003c/em\u003e: A prospective patient is directed to the quiz from our marketing site or from online advertisements. The quiz is treatment-specific (ex. if the patient is seeking treatment for acne, then they use the acne quiz) and asks the patient a series of personal and health-related questions. Once all questions have been answered, the patient enters their shipping and billing information before submitting their quiz. The patient is then redirected to the patient dashboard. Some features of the quiz are:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDifferent question types (ie. free-form, single/multiple choice, image upload)\u003c/li\u003e\n\u003cli\u003eSave and exit a quiz in progress\u003c/li\u003e\n\u003cli\u003eCollect billing and insurance information\u003c/li\u003e\n\u003cli\u003eCustom support chat using Intercom\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003ePatient dashboard\u003c/em\u003e: An existing patient logs into the patient dashboard to manage their treatment. Maybe they want to chat with support, ask their healthcare practitioner a question, or request an early refill of their medication - all of this can be done via the patient dashboard. Patients also use the patient dashboard to manage account settings like shipping and billing information. Some features of the patient dashboard are:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePatient/prescriber chat (text messages, file upload, etc.)\u003c/li\u003e\n\u003cli\u003eManage photo ID, email address, password\u003c/li\u003e\n\u003cli\u003eManage Billing and insurance information\u003c/li\u003e\n\u003cli\u003ePause, resume, cancel treatment\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut of Scope Targets\u003c/h2\u003e\n\n\u003cp\u003e\u003ca href=\"https://bugcrowd.com/engagements/felix-health-mbb-og/attachments/8bf63f28-1fb8-4af0-8a6c-7bc85ed1592c\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eFelix_Out_of_Scope.pdf\u003c/a\u003e\u003c/p\u003e\n\n\u003ch2\u003eOut of Scope Vulnerabilities\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003ePharmacist and Medical Practitioner \u003c/li\u003e\n\u003cli\u003eSocial engineering attempts on our staff including phishing emails\u003c/li\u003e\n\u003cli\u003eVulnerabilities in a vendor we integrate with\u003c/li\u003e\n\u003cli\u003eLack of email address verification during account registration\u003c/li\u003e\n\u003cli\u003eGeneric information disclosure (e.g. stack trace) without additional impact\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ecreate a ticket with Bugcrowd Support\u003c/a\u003e for clarification before proceeding.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":"\u003cul\u003e\n\u003cli\u003eFor both public (no auth) and protected (gated by auth) endpoints, we intentionally use a \u003ccode\u003euuid\u003c/code\u003e to identify resources as a way to \"protect\" the endpoint against IDOR. If an endpoint is public and only identifies resources with \u003ccode\u003euuid\u003c/code\u003e, then any IDOR submission will be marked as informational. We do expect all of these endpoints to be rate limited to prevent uuid enumeration - if one of these endpoints is discovered to not have rate limiting, we consider it a bug.\u003c/li\u003e\n\u003c/ul\u003e"},"scope":[{"id":"b5530b94-631d-4f53-a349-7f90a2d6bfcc","name":"In Scope","targets":[{"id":"bef80221-a229-4e32-9108-77cea27c5a38","uri":"https://bugcrowd.charm.felixforus.ca/home","name":"bugcrowd.charm.felixforus.ca","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"6071ee6e-85ea-4354-9c69-d1c56bfd0fe8","sortOrder":0},"sortOrder":0,"tags":[{"id":"ce8ff3cd-4d54-4404-8321-6351781551a3","name":"Vue.js","targetId":"bef80221-a229-4e32-9108-77cea27c5a38"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"bef80221-a229-4e32-9108-77cea27c5a38"}],"recentChangeFlags":null},{"id":"91d96886-c243-45a3-a1ae-8873e252bc04","uri":"https://bugcrowd.lucky.felixforus.ca","name":"bugcrowd.lucky.felixforus.ca","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"66d7d070-db29-4aab-bd01-0e43b5255672","sortOrder":2},"sortOrder":2,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"91d96886-c243-45a3-a1ae-8873e252bc04"},{"id":"005d6fd9-5c1a-45f7-a2b6-af0e2fdfd820","name":"Laravel","targetId":"91d96886-c243-45a3-a1ae-8873e252bc04"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"91d96886-c243-45a3-a1ae-8873e252bc04"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"48acfae9-ac88-4dac-8e90-f08b748e79f0","p1MaxCents":450000,"p1MinCents":350000,"p2MaxCents":250000,"p2MinCents":150000,"p3MaxCents":75000,"p3MinCents":50000,"p4MaxCents":22500,"p4MinCents":17500,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eTarget Groups\u003c/h2\u003e\n\n\u003cp\u003eThe environment \u003ccode\u003ebugcrowd.\u0026lt;service\u0026gt;.felixforus.ca\u003c/code\u003e is a full-stack deployment of our application created for the bugcrowd program. Internal portal UIs and APIs are out of scope, with the exception of the internal portal login at \u003ccode\u003ebugcrowd.lucky.felixforus.ca/nova/login\u003c/code\u003e.\u003c/p\u003e\n\n\u003ch2\u003eOut of scope\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eFelix\u0026#39;s production application at \u003ccode\u003e*.felixforyou.ca\u003c/code\u003e is strictly out of scope. Experimenting on this application will result in program ban.\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch2\u003e\u003ccode\u003ebugcrowd.charm.felixforus.ca\u003c/code\u003e\u003c/h2\u003e\n\n\u003cp\u003eThis is the primary patient user interface. Patients use this UI for most workflows: complete an onboarding questionnaire, manage their treatment (pause, cancel, resume their medication shipments), chat with their doctor, and find new treatments. \u003cbr\u003e\nTo use this UI, patients must sign in. The only patient workflow that does not require authentication is the first part of the onboarding questionnaire - however, we do require the patient to sign-in midway through.\u003cbr\u003e\nThe application is built using Vue JS with Nuxt JS.\u003c/p\u003e\n\n\u003ch2\u003e\u003ccode\u003ebugcrowd.lucky.felixforus.ca\u003c/code\u003e\u003c/h2\u003e\n\n\u003cp\u003eThis is our primary patient experience API. The primary patient UI (bugcrowd.charm.felixforus.ca) uses this API for all workflows. Some functionality included in this API is: billing, quiz recommendations, and managing treatments (pause, cancel, resume shipments).\u003cbr\u003e\nThis application is build using Laravel.\u003c/p\u003e\n\n\u003ch2\u003e\u003ccode\u003ebugcrowd.lucky.felixforus.ca/nova/login\u003c/code\u003e\u003c/h2\u003e\n\n\u003cp\u003eThe login page for our internal portal, which is its only public entry point. This login page is in scope for security testing. Researchers are encouraged to evaluate the security of the authentication flow and attempt to gain unauthorized access to the portal. Once authenticated access is obtained, all functionality inside the internal portal is strictly out of scope.\u003c/p\u003e","rewardRangeData":{"1":{"min":3500,"max":4500},"2":{"min":1500,"max":2500},"3":{"min":500,"max":750},"4":{"min":175,"max":225},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[{"id":"b1570623-7ebf-4f65-a993-fb35e846a731","attachmentPath":"https://bugcrowd.com/engagements/felix-health-mbb-og/attachments/b1570623-7ebf-4f65-a993-fb35e846a731","name":"Felix_Out_of_scope.pdf","filename":"Felix_Out_of_scope.pdf","description":null,"icon":"fileOther","size":67290,"sizeLabel":"65.7 KB","uploadedAt":"1 Apr 2026","fileType":"Document","embedUrl":"https://bugcrowd.com/engagements/felix-health-mbb-og/attachments/b1570623-7ebf-4f65-a993-fb35e846a731"}],"engagement":{"id":"216c3bba-9e23-4e46-a21c-50bbd1901398","code":"felix-health-mbb-og","state":"in_progress","endsAt":null,"bountyId":"37ec4fcb-a7b5-4bdc-9133-8bf502cdc1c3","startsAt":"2024-09-05T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Healthcare","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/aa93/0793/6159c204/c9cb3f7b36a4fb209f5a0fa06258c3f6_felixhealthca_logo.jpeg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-03-06T17:53:55.052Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/felix-health-mbb-og","changelogs":"/engagements/felix-health-mbb-og/changelog","submissions":null,"announcements":"/engagements/felix-health-mbb-og/announcements","hallOfFame":"/engagements/felix-health-mbb-og/hall_of_fames","crowdstream":"/engagements/felix-health-mbb-og/crowdstream"},"announcementsCount":12,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/felix-health-mbb-og/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=felix-health-mbb-og\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/felix-health-mbb-og/engagement_subscribers","engagementChangelogsUrl":"/engagements/felix-health-mbb-og/changelog","publishedAt":"2026-09-23T17:01:25.709Z","engagementChangelogUrl":"/engagements/felix-health-mbb-og/changelog/fe9726ec-9264-49e8-9fbf-2bb7e7439542","createUserFeedbacksUrl":"/engagements/felix-health-mbb-og/feedbacks","engagementCrowdstreamUrl":"/engagements/felix-health-mbb-og/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}