{"id":"2496a291-97b5-409d-b340-61c25f08f287","engagementId":"a540e9dd-8c47-47d8-90d9-0efc5bcd1cf6","data":{"brief":{"id":"ce2d9303-23c3-41c3-a9c5-7b0ec78c092b","name":"Flourish","tagline":" Create stunning charts, maps and interactive content that engage and inspire - instantly. Help secure the Flourish, we are part of the Canva family!! ","description":"\u003cp\u003eFlourish is an easy to use data visualization and story-telling platform. Here at Flourish we believe no technology is perfect, and we want to have the crowd find security vulnerabilities for us to fix! \u003c/p\u003e\n\n\u003cp\u003eWe take the security of our systems seriously, and we value the security researcher community. Your responsible disclosure of security vulnerabilities by security researchers helps us ensure the security and privacy of our users.\u003c/p\u003e\n\n\u003ch1\u003eGuidelines\u003c/h1\u003e\n\n\u003cp\u003e\u003cstrong\u003eWe require that all researchers:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003e-Include a bug URL in the submission details otherwise the submission will not be accepted\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eMake a every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction of data during security testing\u003c/li\u003e\n\u003cli\u003ePerform research only within the scope set out below\u003c/li\u003e\n\u003cli\u003eUse the identified communication channels to report vulnerability information to us\u003c/li\u003e\n\u003cli\u003eUse your @bugcrowdninja email address when testing\u003c/li\u003e\n\u003cli\u003eUse an X-BugBounty: username header to uniquely tag all attack traffic\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThank you for participating, it is your work that will help to keep us secure.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as In-Scope. \u003cem\u003eAny domain/property of Flourish not listed in the targets section is out of scope. This includes any/all subdomains not listed above.\u003c/em\u003e If you believe you've identified a vulnerability on a system outside the scope, please reach out to support@bugcrowd.com before submitting. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eCredentials\u003c/h3\u003e\n\n\u003cp\u003ePlease sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://researcherdocs.bugcrowd.com/v2.0/docs/your-bugcrowdninja-email-address\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch3\u003eAccess\u003c/h3\u003e\n\n\u003cp\u003eAll targets are publicly accessible.\u003c/p\u003e\n\n\u003ch3\u003eFocus Areas\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe main \u003ca href=\"https://flourish.studio\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eflourish.studio\u003c/a\u003e web application, and \u003ca href=\"https://xyzbmojn.net\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003e*.xyzbmojn.net\u003c/a\u003e assets\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eKnown issues\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eCSRF vulnerabilities in components will be treated as P4 unless you are able to demonstrate ATO. \u003c/li\u003e\n\u003cli\u003eWe have reports of XSS on templates.flourish.studio, preview.flourish.studio, demos.flourish.studio and flo.uri.sh. The fix for this will likely be the same. If a unique report has the same root cause fix it will be a duplicate of the original issue. Reports will be only considered if they are able to prove escalated impact. Any report that describes a complicated way to achieve something that could alternatively be achieved just by uploading a custom template to Flourish will be rejected.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eOut of Scope\u003c/h3\u003e\n\n\u003cp\u003eWe will not accept rate limiting bypass submissions, except where you are able to bypass OTP controls.\u003c/p\u003e\n\n\u003ch3\u003eUntrusted User Content Domains\u003c/h3\u003e\n\n\u003cp\u003eAs part of the Flourish product, the below domains are used to host visualisations from third parties, and as such any vulnerability reports for these domains must show proof of impact for their vulnerabilities, as basic vulnerability PoCs (such as simple XSS or Open Redirect) will not be accepted or rewarded.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eflo.uri.sh\u003c/li\u003e\n\u003cli\u003eflourish-user-templates.com\u003c/li\u003e\n\u003cli\u003eflourish-user-preview.com\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003e3rd party providers\u003c/h3\u003e\n\n\u003cp\u003eThis is within reason. If you discover issues with our AWS or Cloudflare setup, we're going to want to know! But \u003cem\u003emeh\u003c/em\u003e for generic vulnerability reports for third party providers such as:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ehttps://pagely.com/\u003c/li\u003e\n\u003cli\u003ehttps://zendesk.com/\u003c/li\u003e\n\u003cli\u003ehttp://mandrillapp.com\u003c/li\u003e\n\u003cli\u003eThird-party add-ons\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eUnsafe testing\u003c/h3\u003e\n\n\u003cp\u003eIn the interest of the safety of our users, staff, the Internet at large, you must ensure that our users are in no way impacted by your testing. Please ensure you're testing using your own accounts, and do not access user data that you do not own in any way. The following are excluded from scope, and not eligible for a reward:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eIf you discover user or employee credentials, cookies, or API keys (e.g. through dorking or otherwise), please do not attempt to verify them. We will validate credentials and evaluate impact\u003c/li\u003e\n\u003cli\u003ePhysical security tests\u003c/li\u003e\n\u003cli\u003eRubber hose cryptanalysis\u003c/li\u003e\n\u003cli\u003eDoS / DDoS\u003c/li\u003e\n\u003cli\u003ePhishing\u003c/li\u003e\n\u003cli\u003eMalicious software/extensions\u003c/li\u003e\n\u003cli\u003eDisclosure of non-sensitive information, such as product/framework version\u003c/li\u003e\n\u003cli\u003eID enumeration (such as user, design, folder, etc) without any further impact\u003c/li\u003e\n\u003cli\u003eDisclosure of users information that is publicly available\u003c/li\u003e\n\u003cli\u003eInsecure cookie settings for non-sensitive cookies\u003c/li\u003e\n\u003cli\u003eFindings from applications or systems not listed in the ‘Targets’ section\u003c/li\u003e\n\u003cli\u003eFunctional, UI and UX bugs and spelling mistakes\u003c/li\u003e\n\u003cli\u003eReports based on product/protocol version without a proof of concept of exploiting the vulnerability\u003c/li\u003e\n\u003cli\u003eIssues only affecting browsers that Canva does not support, docs located \u003ca href=\"https://support.canva.com/uncategorized/supported-browsers/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":null,"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"0f7a6724-cb87-414c-ba0f-218729ed7262","name":"In Scope Targets","targets":[{"id":"37bc4eb2-7f5a-4a95-9b39-a2655d13e5ff","uri":"https://flo.uri.sh","name":"flo.uri.sh","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"17da6ce6-bf80-4a99-9e97-618c90265c90","sortOrder":0},"sortOrder":0,"tags":[{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"37bc4eb2-7f5a-4a95-9b39-a2655d13e5ff"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"37bc4eb2-7f5a-4a95-9b39-a2655d13e5ff"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"37bc4eb2-7f5a-4a95-9b39-a2655d13e5ff"}],"recentChangeFlags":null},{"id":"23efb360-e541-4696-a3a7-7dd705c2c5d0","uri":"https://flourish.studio/","name":"*.flourish.studio","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e2e5354a-bd56-431c-974b-f72cc7a965b2","sortOrder":0},"sortOrder":0,"tags":[{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"23efb360-e541-4696-a3a7-7dd705c2c5d0"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"23efb360-e541-4696-a3a7-7dd705c2c5d0"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"23efb360-e541-4696-a3a7-7dd705c2c5d0"}],"recentChangeFlags":null},{"id":"83c15dcc-ab24-448f-91f7-c282207e404f","uri":"https://xyzbmojn.net/","name":"*.xyzbmojn.net","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"474ff371-bfba-4ea5-bd30-a0c1ba3cd847","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"38ea1ef8-ed40-42e1-aa61-a04bdd34dc32","uri":"","name":"flourish-user-templates.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"c091f351-24b4-46da-a843-75c2303bae2d","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"748126e8-fe59-4dcf-87fe-bc9ba4fd05ea","uri":"","name":"flourish-user-preview.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"45da1c2e-8ab7-4580-8053-bb65fd3ee7d0","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"829ff6db-2a26-4d90-ac55-b5b4fba8cf74","uri":"https://*.kiln.it","name":"*.kiln.it","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e76acfa1-459e-49f5-b944-4811c24cd3be","sortOrder":5},"sortOrder":5,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"a0fabdd2-6310-4dd0-aa35-114029d957fa","p1MaxCents":600000,"p1MinCents":600000,"p2MaxCents":250000,"p2MinCents":250000,"p3MaxCents":85000,"p3MinCents":85000,"p4MaxCents":10000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":6000,"max":6000},"2":{"min":2500,"max":2500},"3":{"min":850,"max":850},"4":{"min":100,"max":100},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"57aa058d-e0af-4654-933e-c94dce20c652","name":"Out of Scope Targets","targets":[{"id":"26d91b7b-e46d-42d1-9efb-76b703afa6d9","uri":"https://training.flourish.studio","name":"training.flourish.studio","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"98744b57-61c0-4ff9-85f3-ef3f5a91813a","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"a540e9dd-8c47-47d8-90d9-0efc5bcd1cf6","code":"flourish","state":"in_progress","endsAt":null,"bountyId":"20372fcb-ec16-4a08-a13e-b2fff4d628d7","startsAt":"2021-08-03T00:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/engagement_brief_logos/engagement_brief/logo/ce2d9303-23c3-41c3-a9c5-7b0ec78c092b/7537e0eb-28e7-4e0c-aab9-57130d2c7c91.png","logoBackgroundColor":"#FFFFFF","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2021-08-03T00:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/flourish","changelogs":"/engagements/flourish/changelog","submissions":null,"announcements":"/engagements/flourish/announcements","hallOfFame":"/engagements/flourish/hall_of_fames","crowdstream":"/engagements/flourish/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/flourish/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=flourish\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/flourish/engagement_subscribers","engagementChangelogsUrl":"/engagements/flourish/changelog","publishedAt":"2026-09-09T03:58:28.681Z","engagementChangelogUrl":"/engagements/flourish/changelog/2496a291-97b5-409d-b340-61c25f08f287","createUserFeedbacksUrl":"/engagements/flourish/feedbacks","engagementCrowdstreamUrl":"/engagements/flourish/crowdstream","acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}