{"id":"486b3cf6-80f0-440c-8aa4-564a2fe7df03","engagementId":"54388439-b9d5-4aab-8903-a5c6548aec67","data":{"brief":{"id":"ef473af0-f42d-4ed1-b5f8-711a23fa2c0a","name":"Federal Trade Commission: Vulnerability Disclosure Program","tagline":"Report FTC Site Vulnerabilities! ","description":"\u003cp\u003eAs provided in OMB M-20-32 and DHS CISA BOD 20-01 (Sept. 2, 2020), Federal policy encourages good-faith research, discovery, and reporting of vulnerabilities in U.S. Government web sites and other internet-accessible systems or services.\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"2a38890b-c88e-4bc0-8db0-02059f3fafe6","targetsOverview":"\u003ch2\u003eHow to report\u003c/h2\u003e\n\n\u003cp\u003eIn accordance with the above policy, we request that vulnerabilities, if any, found only on the following FTC web sites be reported to us by using the \"Submit report\" button on this web page. (More FTC domains may be added to the list of targets in the future.)\u003c/p\u003e\n\n\u003ch1\u003eWhat to report\u003c/h1\u003e\n\n\u003cp\u003ePlease provide information to assist the FTC in finding and analyzing the vulnerability, including for example a description of the vulnerability, its location (e.g. full URL), the potential impact, technical information needed to reproduce the vulnerability, any proof of concept code, and any other information you may believe is relevant or necessary for the FTC to identify and remedy the vulnerability. You need not include personally identifying information (PII) about yourself when submitting a report, but we request that you provide us a way to contact you if you want us to acknowledge your request, and for us to follow up with additional questions, if necessary.\u003c/p\u003e\n\n\u003cp\u003eReports may be submitted anonymously. If you provide us your contact information, we will acknowledge your report within 3 business days.\u003c/p\u003e\n\n\u003ch2\u003eWhat activities are allowed or prohibited\u003c/h2\u003e\n\n\u003cp\u003eThis policy is not intended to prohibit vulnerability testing that does not compromise the confidentiality, integrity, or availability, or otherwise interfere with the operation, of the FTC systems and services within the scope of this policy. The following activities are not authorized:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNetwork denial of service (DoS or DDoS) tests\u003c/li\u003e\n\u003cli\u003ePhysical testing (e.g. office access, open doors, tailgating), social engineering (e.g., phishing, vishing), or any other non-technical vulnerability testing\u003c/li\u003e\n\u003cli\u003eDisclosure to any party (other than reporting to the FTC) of PII acquired from an FTC system\u003c/li\u003e\n\u003cli\u003eResearch activities that would violate the rights any other individual or entity\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eWhat to expect\u003c/h2\u003e\n\n\u003cp\u003eIn addition to acknowledging your request as noted above, we will confirm, where possible, whether the vulnerability exists, and let you know, as appropriate, what steps we are taking during the remediation process, including issues or challenges that may delay resolution. We may be unable to share certain information for security or legal reasons. We cannot provide “bug bounties” or rewards, and you understand and agree that the FTC will not compensate you for reporting vulnerabilities. In addition, where necessary, we may be required to share reports with other agencies or entities to investigate or otherwise assist us in remediating reported vulnerabilities, or as otherwise authorized or required by law.\u003c/p\u003e\n\n\u003ch2\u003eLegal\u003c/h2\u003e\n\n\u003cp\u003eYou must comply with all applicable Federal, State, and local laws in connection with your security research activities or other participation in this vulnerability disclosure program. We do not authorize, permit, or otherwise allow (expressly or impliedly) any person, including any individual, group of individuals, consortium, partnership, or any other business or legal entity to engage in any security research or vulnerability or threat disclosure activity that is inconsistent with this policy or the law. If you engage in any activities that are inconsistent with this policy or the law, you may be subject to criminal and/or civil liabilities.\u003c/p\u003e\n\n\u003cp\u003eBy submitting a report to the FTC, researchers warrant that the report and any attachments do not violate the intellectual property rights of any third party and the submitter grants the FTC a non-exclusive, royalty-free, world-wide, perpetual license to use, reproduce, create derivative works, and publish the report and any attachments.\u003c/p\u003e\n\n\u003cp\u003eExcept as authorized or required by law, we do not intend to recommend legal action against security research activities that we believe are authorized and represent a good-faith effort to follow the above policy.\u003c/p\u003e\n\n\u003cp\u003eWe may modify the terms of this policy or terminate the policy at any time.\u003c/p\u003e\n\n\u003ch2\u003eQuestions\u003c/h2\u003e\n\n\u003cp\u003eQuestions regarding this policy may be submitted to security@ftc.gov. We currently do not support PGP-encrypted e-mails.\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003cp\u003eThe Cybersecurity and Infrastructure Security Agency (CISA) Vulnerability Disclosure Policy Platform (VDP Platform) gives agencies the option to use a centrally managed system to intake vulnerability information from and collaborate with the public to improve the security of their internet-accessible systems. CISA has a contract with EnDyna and Bugcrowd, private companies, to manage the platform used by the public to report vulnerability information; CISA exercises general oversight of the program.  CISA does not collect, maintain, use, or disseminate any Personally Identifiable Information (PII) provided to Bugcrowd for the purposes of creating a profile on the website or reporting a vulnerability to agencies other than CISA.  Participating agencies provide their own program vulnerability disclosure policy, setting out the agency’s parameters for vulnerability disclosures, including provisions for collection and use of submitted information. Any submissions of vulnerabilities pertaining to CISA’s own information systems would be governed by the DHS VDP brief.\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"27881dfd-1fa1-4b86-a7e7-764261586704","name":"In Scope Targets","targets":[{"id":"65087438-b3d8-4d57-af93-56224948f2f3","uri":"https://www.alertaenlinea.gov","name":"https://*.alertaenlinea.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"4e3c206c-6924-4be3-823e-be115a8075c2","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"f20818f7-890d-4ef5-bc3e-c1182918c5d4","uri":"https://www.consumer.gov","name":"https://*.consumer.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"df1a201c-4eb2-476a-ac89-8e11981f475f","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"75315244-5c71-4f45-9148-09e12b24ae83","uri":"https://www.consumersentinel.gov","name":"https://*.consumersentinel.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"60b16e2a-3075-415e-8366-27b15d53c04e","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"1821ea54-4f17-4e02-b786-6623ecac340c","uri":"https://consumidor.gov","name":"https://*.consumidor.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"553c393a-cd66-48a5-9e4b-e2ced59193de","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"eec148fa-4fd6-465b-8fd8-3c6282f26e8f","uri":"https://www.donotcall.gov","name":"https://*.donotcall.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"2ca2f0c8-b9f8-4804-96ee-b3257e43c08b","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"f5e619ae-c451-4a43-97bd-e0e3e47e0b06","uri":"https://www.dontserveteens.gov","name":"https://*.dontserveteens.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"b8070ced-e9c7-4a04-a2b3-b71b46e68ad2","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"b03a3289-a366-40fd-bca5-d1d71a640fb7","uri":"https://www.econsumer.gov","name":"https://*.econsumer.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ce1b7ced-9b5e-4ec8-be59-c772596b5d18","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"ac68a248-4f57-4040-b09a-32482e4e9932","uri":"https://www.ftc.gov","name":"https://*.ftc.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"48ba38fc-594f-42e6-be47-ad2edd57278e","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"3629b35b-736e-46c3-a8de-72055b7a900e","uri":"https://www.hsr.gov","name":"https://*.hsr.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"7f8e01c7-ba1d-405c-b1d2-3dcd397d0563","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"2108a140-1ff0-42d1-a965-ff488f40173e","uri":"https://www.identitytheft.gov","name":"https://*.identitytheft.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"fd9fbca8-4489-42f1-87b6-43aa945a856c","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"776d5638-bc1d-44a8-8f82-49b541c5953c","uri":"https://www.militaryconsumer.gov","name":"https://*.militaryconsumer.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"711003eb-078d-44a0-8854-385c89efa162","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"f0592e4b-a965-4b0d-b789-5bf350454de5","uri":"https://www.onguardonline.gov","name":"https://*.onguardonline.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"1c0cbf2b-d283-464f-afbf-114ee373269a","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"ef086523-c816-4f57-974a-37d77e0e152b","uri":"https://www.robodeidentidad.gov","name":"https://*.robodeidentidad.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"9f3a5a4f-41fd-46bb-8c7d-0b3a60d8ae30","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"8bd49a56-32dd-48f3-a0e4-46004c6fabf5","uri":"https://www.sentinel.gov","name":"https://*.sentinel.gov","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"eb73dce8-c537-4053-ae55-fdfb6ca549bb","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"54388439-b9d5-4aab-8903-a5c6548aec67","code":"ftc-vdp","state":"in_progress","endsAt":null,"bountyId":"071966f9-0a0e-4a82-a5c8-e41d298d4661","startsAt":"2022-09-26T16:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Government","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/1e76/448a/b640eaa3/f01aed457a7e94174d5a5b5c16cfcf4e_cghx_g3W_400x400.jpeg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2022-09-26T16:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/ftc-vdp","changelogs":"/engagements/ftc-vdp/changelog","submissions":null,"announcements":"/engagements/ftc-vdp/announcements","hallOfFame":"/engagements/ftc-vdp/hall_of_fames","crowdstream":"/engagements/ftc-vdp/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Priority Triage","submitReportUrl":"/engagements/ftc-vdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=ftc-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/ftc-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/ftc-vdp/changelog","publishedAt":"2026-02-04T18:36:10.912Z","engagementChangelogUrl":"/engagements/ftc-vdp/changelog/486b3cf6-80f0-440c-8aa4-564a2fe7df03","createUserFeedbacksUrl":"/engagements/ftc-vdp/feedbacks","engagementCrowdstreamUrl":"/engagements/ftc-vdp/crowdstream","acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}