{"id":"cceb97f9-3e7d-4114-a123-bbd4d2debbfe","engagementId":"02c56af7-fa05-4553-8a53-3644778833fd","data":{"brief":{"id":"bb8cccf6-a816-437b-b713-0ae563d18d80","name":"Gap Inc.","tagline":"Fashion \u0026 Apparel for Men, Women \u0026 Kids","description":"\u003ch1\u003eWelcome to \u003cstrong\u003eGap Inc's.\u003c/strong\u003e Responsible Disclosure Program\u003c/h1\u003e\n\n\u003chr\u003e\n\n\u003cp\u003eGapTech is the award-winning e-commerce division of Gap Inc. At GapTech, we drive innovation in retail while striving to guarantee that a great deal on a new pair of jeans is also a safe \u0026amp; secure transaction. We believe in fostering collaboration with skilled security researchers and that security can be fashionable too.\u003c/p\u003e\n\n\u003ch2\u003e\u003cstrong\u003eIMPORTANT: Confidentiality \u0026amp; Disclosure Policy\u003c/strong\u003e\u003c/h2\u003e\n\n\u003cp\u003ePublic disclosure (including via social media, forums, or blogs) is not permitted. All information relating to this Programme and any identified vulnerabilities must be treated as confidential.\u003c/p\u003e\n\n\u003cp\u003eSubmissions that do not adhere to this non-disclosure policy may be considered out of scope and could result in loss of participation eligibility.\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch2\u003e!!Challenge Coins | Available for a limited time!!\u003c/h2\u003e\n\n\u003cp\u003eWe currently have a limited number of Gap Challenge coins available to distribute. To get your hands on one of these limited coins, all you need to do is submit a valid P1 or P2 finding. This offer is valid from July 9th 2025 until stocks last.\u003c/p\u003e","industryTagId":"9ed1ce49-a148-438f-92d3-0b8d70b6a8ae","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of GAP not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to GAP, you can report it to this engagement.\u003c/p\u003e\n\n\u003cp\u003eTesting is limited to the assets listed as in scope. The AI chat functionality used for customer support within the Gap application is out of scope.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eFocus Areas\u003c/h3\u003e\n\n\u003cp\u003eThese focus areas apply to the purchase and checkout flow of gap.com, including endpoints like the shopping bag, checkout, and place order pages. Researchers are encouraged to explore the following areas to identify impactful vulnerabilities that could affect user data, rewards, or order processing.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003eAuthentication/Session Issues\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003e• Reuse or tampering of session identifiers (e.g., CAM cookies or external customer IDs) to impersonate or act on behalf of other users.\u003cbr\u003e\n• Accessing another user’s cart, order history, or account details by manipulating request parameters.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003cstrong\u003eInsecure Direct Object Reference (IDOR)\u003c/strong\u003e\u003cbr\u003e\n• Modifying object IDs (e.g., orderId) to access or manipulate other customers’ data.\u003cbr\u003e\n• Attempting unauthorised use of gift cards, coupons, or saved payment methods.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003cstrong\u003eBusiness Logic Bypass\u003c/strong\u003e\u003cbr\u003e\n• Placing orders with unauthorised discounts by manipulating reward points, promo codes, or price values.\u003cbr\u003e\n• Bypassing quantity or item restrictions, such as ordering more than allowed or restricted items.\u003cbr\u003e\n• Changing shipping fees, item prices, or applying expired coupons.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003cstrong\u003eAbuse of Reward Systems\u003c/strong\u003e\u003cbr\u003e\n• Reusing or inflating reward points.\u003cbr\u003e\n• Stacking incompatible discounts or coupons by modifying request payloads.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003cstrong\u003eCheckout Flow Manipulation\u003c/strong\u003e\u003cbr\u003e\n• Skipping mandatory steps (e.g., shipping address, payment validation) to place an order.\u003cbr\u003e\n• Triggering unintended order states or duplicate submissions.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003cstrong\u003eSensitive Data Exposure\u003c/strong\u003e\u003cbr\u003e\n• Unauthorized access to PII (e.g., name, address, phone number) of other users.\u003cbr\u003e\n• Reviewing how error messages or debug info could leak sensitive information.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003cstrong\u003eClient-Side Tampering\u003c/strong\u003e\u003cbr\u003e\n• Modifying frontend JavaScript or intercepting and altering requests to bypass validations.\u003cbr\u003e\n• Changing UI flow or inputs to unlock hidden or unintended functionality.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eRecent Updates\u003c/h2\u003e\n\n\u003cp\u003eWithin the\u003ccode\u003e*.gap.com\u003c/code\u003e section of the scope you can find our \u003cstrong\u003eNew Loyalty Rewards Program\u003c/strong\u003e  which was recently launched in conjunction with our 4 BRANDS, ONE EASY CHECKOUT initiative, however this \u003cstrong\u003edoes not include the rewards credit card\u003c/strong\u003e. \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eGap: \u003ca href=\"https://www.gap.com/customerService/info.do?cid=1099008\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eGood Gap Rewards\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eOldNavy: \u003ca href=\"https://oldnavy.gap.com/customerService/info.do?cid=1095422\u0026amp;mlink=5252%2C1%2CGB_LoyaltyAcq\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNavyist Rewards\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003eBanana Republic: \u003ca href=\"https://bananarepublic.gap.com/customerService/info.do?cid=1098875\u0026amp;mlink=5001,26933946,swb_ilp_detailsandapplynow\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBanana Republic Rewards\u003c/a\u003e\n\u003c/li\u003e\n\u003cli\u003e Athleta: \u003ca href=\"https://athleta.gap.com/browse/info.do?cid=1098761\u0026amp;terms-conditions=1\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAthleta Rewards\u003c/a\u003e \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eProhibited Activity and Exclusions\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eAutomated vulnerability scanners. We need your brainpower, not your processing power. Lockouts for surpassing normal bandwidth will be enforced.\u003c/li\u003e\n\u003cli\u003eWifi or supporting infrastructure of \u003cem\u003eGap Inc.\u003c/em\u003e  stores or offices\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eThe following finding types are specifically excluded from the program\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eSPF/DMARC records\u003c/li\u003e\n\u003cli\u003eCookie Flags (Secure/HTTPOnly)\u003c/li\u003e\n\u003cli\u003eClickjacking\u003c/li\u003e\n\u003cli\u003eLogin or Forgot Password page brute force\u003c/li\u003e\n\u003cli\u003eUsername enumeration via Login Page error message\u003c/li\u003e\n\u003cli\u003eUsername enumeration via Forgot Password error message\u003c/li\u003e\n\u003cli\u003eRate-limiting issues\u003c/li\u003e\n\u003cli\u003eDoS/DDoS\u003c/li\u003e\n\u003cli\u003eAutocomplete attribute on web forms\u003c/li\u003e\n\u003cli\u003eDescriptive error messages (e.g. Stack Traces, application or server errors).\u003c/li\u003e\n\u003cli\u003eDisclosure of known public files or directories\u003c/li\u003e\n\u003cli\u003eUse of outdated software/library versions\u003c/li\u003e\n\u003cli\u003eHTTP 404 codes/pages or other HTTP non-200 codes/pages.\u003c/li\u003e\n\u003cli\u003eBanner disclosure on common/public services.\u003c/li\u003e\n\u003cli\u003eCSRF on forms that are available to anonymous users (e.g. the contact form).\u003c/li\u003e\n\u003cli\u003eLogout Cross-Site Request Forgery (logout CSRF).\u003c/li\u003e\n\u003cli\u003ePresence of application or web browser ‘autocomplete’ or ‘save password’ functionality.\u003c/li\u003e\n\u003cli\u003eLack of Security Speedbump when leaving the site.\u003c/li\u003e\n\u003cli\u003eOPTIONS / TRACE HTTP method enabled\u003c/li\u003e\n\u003cli\u003eThe Anti-MIME-Sniffing header X-Content-Type-Options\u003c/li\u003e\n\u003cli\u003eMissing HTTP security headers, specifically (https://blog.veracode.com/2014/03/guidelines-for-setting-security-headers/)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"089da0a9-28f2-4b1b-b9d7-3c5be739b631","name":"In Scope Web Targets ","targets":[{"id":"054a7f24-a302-48f2-81a0-ca6d77468053","uri":"https://gap.com","name":" *.gap.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"3c95e900-56e6-4b13-ac55-305ee278c463","sortOrder":0},"sortOrder":0,"tags":[{"id":"08e84ba6-1e84-4c11-b559-a3b3b963546f","name":"Akamai CDN","targetId":"054a7f24-a302-48f2-81a0-ca6d77468053"},{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"054a7f24-a302-48f2-81a0-ca6d77468053"},{"id":"3585ef4a-cd09-429b-ad25-5777064e59c5","name":"Moment.js","targetId":"054a7f24-a302-48f2-81a0-ca6d77468053"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"054a7f24-a302-48f2-81a0-ca6d77468053"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"054a7f24-a302-48f2-81a0-ca6d77468053"},{"id":"a5bf7fc5-03c4-42f4-b10d-5ceb23d1c064","name":"Lodash","targetId":"054a7f24-a302-48f2-81a0-ca6d77468053"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"054a7f24-a302-48f2-81a0-ca6d77468053"},{"id":"c3412833-26e7-4bbd-907f-760d9da61232","name":"Newrelic","targetId":"054a7f24-a302-48f2-81a0-ca6d77468053"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"054a7f24-a302-48f2-81a0-ca6d77468053"}],"recentChangeFlags":null},{"id":"9e0e3b35-6cbd-4e02-9b31-5db59bcff9ae","uri":"https://gap.com/shopping-bag","name":"https://gap.com/shopping-bag","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"499a8f68-23dd-44a5-8ba3-a016d9ad0f90","sortOrder":1},"sortOrder":1,"tags":[{"id":"624f911d-7e8c-4d56-b523-e7416c1cc319","name":"NextJS","targetId":"9e0e3b35-6cbd-4e02-9b31-5db59bcff9ae"},{"id":"a5bf7fc5-03c4-42f4-b10d-5ceb23d1c064","name":"Lodash","targetId":"9e0e3b35-6cbd-4e02-9b31-5db59bcff9ae"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"9e0e3b35-6cbd-4e02-9b31-5db59bcff9ae"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"9e0e3b35-6cbd-4e02-9b31-5db59bcff9ae"}],"recentChangeFlags":null},{"id":"bd075a8c-c873-4fb7-976a-011d3a901944","uri":"https://gap.com/checkout","name":"https://gap.com/checkout","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"eccce18c-bc30-4cd7-9414-a185a5197878","sortOrder":2},"sortOrder":2,"tags":null,"recentChangeFlags":null},{"id":"463ec002-f1ed-4979-9517-9afa9b628308","uri":"https://secure-www.gap.com/checkout/place-order/","name":"https://secure-www.gap.com/checkout/place-order/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"0be249f7-5638-4f55-9cb3-2b17e3ccb9c4","sortOrder":3},"sortOrder":3,"tags":null,"recentChangeFlags":null},{"id":"6527f3ff-716c-4ab4-aab1-ef439e2c1fd1","uri":"","name":"https://secure-www.gap.com/checkout/place-order/xapi/update-payment-method-action","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"eb9bf190-5157-4502-ac8a-9d2ed09277fe","sortOrder":4},"sortOrder":4,"tags":null,"recentChangeFlags":null},{"id":"c26be82f-2a2c-4e8b-8464-6ab96ea4cf36","uri":"","name":"https://secure-www.gap.com/checkout/place-order/xapi/place-order-action","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f4b6a961-aa04-4f34-a481-51f06c65d7dc","sortOrder":5},"sortOrder":5,"tags":null,"recentChangeFlags":null},{"id":"bc5fa1bf-4b95-45bf-a63d-c8775d3f95f2","uri":"","name":"https://api.gap.com/credit_cards/v1/?external_customer_id=","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"0bf1902a-1dc4-44bd-b7a9-162d3e28beaf","sortOrder":6},"sortOrder":6,"tags":null,"recentChangeFlags":null},{"id":"0f131fe1-a1ef-4dcd-b901-041ede294e98","uri":"","name":"https://api.gap.com/","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"11112d3f-939e-411e-aa8a-6733b1261fef","sortOrder":7},"sortOrder":7,"tags":null,"recentChangeFlags":null},{"id":"76c4e818-97b0-4abb-a753-4899bb42b828","uri":"","name":"https://secure-www.gap.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"98ed94bf-3973-4c7e-9e6e-489fafc8c319","sortOrder":8},"sortOrder":8,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003ch2\u003eTarget Information\u003c/h2\u003e\n\n\u003cp\u003eThis is meant to be comprehensive of all GAP Inc. owned websites. \u003c/p\u003e\n\n\u003cp\u003eGap Inc. Brands\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eGap\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eOld Navy\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eBanana Republic\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eAthleta\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{},"recentChangeFlags":null},{"id":"c47f80d0-7c16-4722-b0e0-55c164811ad0","name":"In Scope Mobile Targets ","targets":[{"id":"8476d1c9-3789-4fd6-8954-006e343557ba","uri":"https://play.google.com/store/apps/details?id=com.skava.hybridapp.gap\u0026hl=en_US\u0026gl=US","name":"Gap (Android) ","category":"android","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6e09c15a-a334-4630-8f9b-6c8f747117fa","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"8476d1c9-3789-4fd6-8954-006e343557ba"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"8476d1c9-3789-4fd6-8954-006e343557ba"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"8476d1c9-3789-4fd6-8954-006e343557ba"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"8476d1c9-3789-4fd6-8954-006e343557ba"}],"recentChangeFlags":null},{"id":"66b5d874-8e93-4cf0-bb33-69a3e4f03431","uri":"https://apps.apple.com/us/app/gap/id326347260","name":"Gap (iOS)","category":"ios","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"98b8d038-618b-404b-9c5b-4ae979821d11","sortOrder":0},"sortOrder":0,"tags":[{"id":"63c4a71d-215f-49ca-8ea8-240dfbf82d61","name":"Objective-C","targetId":"66b5d874-8e93-4cf0-bb33-69a3e4f03431"},{"id":"7692155d-e2db-4c50-abd5-208448a85fde","name":"SwiftUI","targetId":"66b5d874-8e93-4cf0-bb33-69a3e4f03431"},{"id":"a47bcaa8-a080-4539-b4ca-e699e72d2023","name":"Swift","targetId":"66b5d874-8e93-4cf0-bb33-69a3e4f03431"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"66b5d874-8e93-4cf0-bb33-69a3e4f03431"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"66b5d874-8e93-4cf0-bb33-69a3e4f03431"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null},{"id":"b0c6895d-95b8-49d2-9b34-bc28281adee8","name":"Out of Scope","targets":[{"id":"17eb42f1-9d37-43f4-93d5-4e08cf6a65fa","uri":null,"name":"equality.gapinc.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"bbbca6e7-4251-4980-b72c-a4ca430f60c8","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"17eb42f1-9d37-43f4-93d5-4e08cf6a65fa"}],"recentChangeFlags":null},{"id":"831afe50-b565-412a-8c21-15cfbf507196","uri":null,"name":"investors.gapinc.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"baa5653a-be74-409b-a98c-c20436b938b1","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"831afe50-b565-412a-8c21-15cfbf507196"}],"recentChangeFlags":null},{"id":"489b3fd7-6508-4ae1-9762-0db76fefc53e","uri":null,"name":"Recruiting - jobs.gapinc.com, careersblog.gapinc.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6fc4ecc8-bd7c-48d7-856e-965c7e955afc","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"489b3fd7-6508-4ae1-9762-0db76fefc53e"}],"recentChangeFlags":null},{"id":"6f6243ca-1d31-4765-a29b-e7ea7fb8e518","uri":null,"name":"*.gaptech.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"4080c2d6-6a54-4f77-88f0-9cf16d143751","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"6f6243ca-1d31-4765-a29b-e7ea7fb8e518"}],"recentChangeFlags":null},{"id":"66064ea0-b427-4461-90c7-b956c905b243","uri":"","name":"*.gap.com.mx","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"a75bbb6d-56f1-4176-98f0-b944a935783b","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"f2dac548-a02d-4497-b085-c0d2bbb20400","uri":"","name":"*.liverpool.com.*","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"bab4ac17-3a20-49f2-82bd-9756b1b9c0f9","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"010512cc-bad7-47c5-9340-4a980cef71b7","uri":"","name":"Janie \u0026 Jack ","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"15c1b417-235f-4141-a0bd-e6baf8bf7304","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"80daef83-9c85-47ac-b9c5-32bc72209ca6","uri":"","name":"Intermix","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"270321fa-7470-4005-9f86-655fcbe2067c","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":2,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eDo not Test any Liverpool or mexico domains applications\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"02c56af7-fa05-4553-8a53-3644778833fd","code":"gapinc","state":"in_progress","endsAt":null,"bountyId":"2d0313df-85a7-4637-a588-19110a56bb11","startsAt":"2017-04-11T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Retail","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/9b0a/cf4a/6f430226/1f1ab95565434c72beace59897ead0ce_d37b3f9fb0a5e7246327ba9823a7ea4d6e133261_xtralarge.png","logoBackgroundColor":"#007DBB","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2026-01-05T15:50:18.986Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/gapinc","changelogs":"/engagements/gapinc/changelog","submissions":null,"announcements":"/engagements/gapinc/announcements","hallOfFame":"/engagements/gapinc/hall_of_fames","crowdstream":"/engagements/gapinc/crowdstream"},"announcementsCount":25,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/gapinc/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=gapinc\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/gapinc/engagement_subscribers","engagementChangelogsUrl":"/engagements/gapinc/changelog","publishedAt":"2026-08-14T09:41:39.117Z","engagementChangelogUrl":"/engagements/gapinc/changelog/cceb97f9-3e7d-4114-a123-bbd4d2debbfe","createUserFeedbacksUrl":"/engagements/gapinc/feedbacks","engagementCrowdstreamUrl":"/engagements/gapinc/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}