{"id":"e57fb9c2-18c7-4440-891f-d7fd8857088c","engagementId":"c4bbb2cf-1b0a-4439-a784-066a18e53e0f","data":{"brief":{"id":"f1734494-797a-4e52-8814-c2ebb5bfd8e1","name":"HostGator LATAM Bug Bounty","tagline":"HostGator LATAM is the division of the global web hosting provider HostGator that serves Latin American markets, offering localized web hosting solutions, including shared hosting, WordPress hosting, and VPS hosting, tailored to the needs of businesses and individuals in the region.","description":"\u003cp\u003eWe appreciate your efforts and hard work in making the internet (and HostGator LATAM) more secure, and look forward to working with the researcher community to create a meaningful and successful bug bounty program. If you believe you have discovered a vulnerability in our service, we encourage you to report it responsibly through this program. We will review, validate, and address any vulnerabilities in accordance with Bugcrowd’s responsible disclosure guidelines, ensuring prompt responses and appropriate remediation. Good luck and happy hunting!\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eEligibility\u003c/h2\u003e\n\n\u003cp\u003eYou may not participate in this program if you are an employee or family member of an employee, or a current vendor or employee of such vendor of Newfold Digital and any of its subsidiaries. You are also prohibited from participating if you are (i) in a country or territory that is the target of U.S. sanctions (including Cuba, Iran, Syria, North Korea, or the Crimea region of Ukraine), (ii) designated as a Specially Designated National or Blocked Person by the U.S. Department of the Treasury’s Office of Foreign Assets Control or otherwise owned, controlled, or acting on behalf of such a person or entity, or (iii) otherwise a prohibited party under U.S. trade and export control laws. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003eThe program relies on CVSS to evaluate impact and determine reward allocations. It is essential to highlight that the priority of a vulnerability might be altered due to following:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe severity of the vulnerability (CVSS rating)\u003c/li\u003e\n\u003cli\u003eThe likelihood of exploit\u003c/li\u003e\n\u003cli\u003eThe impact of exploit\u003c/li\u003e\n\u003cli\u003eAny other factor at our discretion\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCVSS Score\u003c/th\u003e\n\u003cth\u003eVRT Classification\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e9.0-10.0\u003c/td\u003e\n\u003ctd\u003eP1-Critical\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e7.0-8.9\u003c/td\u003e\n\u003ctd\u003eP2-High\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e4.0-6.9\u003c/td\u003e\n\u003ctd\u003eP3-Medium\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e2.0-3.9\u003c/td\u003e\n\u003ctd\u003eP4-Low\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e0.0-1.9\u003c/td\u003e\n\u003ctd\u003eP5-Informational\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003cp\u003eWe reserve the right to make any final determination of rating levels for any reported vulnerability. \u003c/p\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003chr\u003e\n\n\u003ch2\u003eAccess/Credentials\u003c/h2\u003e\n\n\u003cp\u003eNo credentials will be provided for testing. For any areas that allow a signup you may use your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e. \u003c/p\u003e\n\n\u003cp\u003eNote:  You will not be reimbursed for any charges you may incur during signup or testing.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eProgram Rules\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eDo not create multiple accounts for testing purposes within HostGator LATAM applications and services. \u003c/li\u003e\n\u003cli\u003eRefrain from using brute force techniques to assess API rate limiting or other functionalities.\u003c/li\u003e\n\u003cli\u003ePhishing, vishing, smishing, or any other forms of social engineering are strictly prohibited. \u003c/li\u003e\n\u003cli\u003eEnsure efforts are made to avoid privacy violations, data destruction, and disruption or degradation of service. \u003c/li\u003e\n\u003cli\u003eOnly interact with accounts you own or have explicit permission to use. Unblocking restricted accounts is not guaranteed. Requests for review can be submitted through Bugcrowd for consideration by the HostGator LATAM InfoSec team. \u003c/li\u003e\n\u003cli\u003eTesting is only permitted on components directly controlled by our program; third-party assets are excluded. \u003c/li\u003e\n\u003cli\u003eInteracting with real customers or real customer accounts is forbidden. \u003c/li\u003e\n\u003cli\u003eWhen a vulnerability consists of different parameters but having the same endpoint, please group this together in the same report else will be considered as duplicate. \u003c/li\u003e\n\u003cli\u003eMultiple vulnerabilities caused by one underlying issue will be awarded one bounty (Ex: Centralized vulnerable parameters). \u003c/li\u003e\n\u003cli\u003eCross-Site Scripting (XSS) attacks are considered at maximum a medium severity. \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut of Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eNo DMARC, nor SPF \u003c/li\u003e\n\u003cli\u003eDos/DDos(Rate Limiting) \u003c/li\u003e\n\u003cli\u003eOAuth session token is not invalidated on logout or password change/reset \u003c/li\u003e\n\u003cli\u003eOpen redirect vulnerabilities\u003c/li\u003e\n\u003cli\u003eError messages (e.g. verbose error messages, stack traces, application or server errors, version disclosure) \u003c/li\u003e\n\u003cli\u003eClickjacking \u003c/li\u003e\n\u003cli\u003eMissing or misconfigured HTTP security header \u003c/li\u003e\n\u003cli\u003eHTTP/DNS cache poisoning \u003c/li\u003e\n\u003cli\u003eCloudflare related issues \u003c/li\u003e\n\u003cli\u003eSelf-XSS reports will not be accepted\u003c/li\u003e\n\u003cli\u003eBroken links hosted on our website\u003c/li\u003e\n\u003cli\u003eSecrets such as API keys or passwords obtained from external aggregation/indexed data sources (e.g., dehashed.com or intelx.io). Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with non-sensitive actions (including logout CSRF) \u003c/li\u003e\n\u003cli\u003eRecently disclosed (\u0026lt;30 days) zero-day vulnerabilities\u003c/li\u003e\n\u003cli\u003ePlease do not test chatboxes on the applications, etc. \u003c/li\u003e\n\u003cli\u003eUse of third-party vulnerable components\u003c/li\u003e\n\u003cli\u003eAnti Automation attacks, missing captcha, missing rate limiting, HTTP headers, SSL/TLS configuration and missing Secure flag on cookies are out of scope \u003c/li\u003e\n\u003cli\u003eAny source code disclosure\u003c/li\u003e\n\u003cli\u003eInfo.php (without providing an exploitable scenario) \u003c/li\u003e\n\u003cli\u003eSubdomain takeovers\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support \u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"a9a51f7f-f384-4f51-b375-936152322d03","name":"In Scope","targets":[{"id":"febd2464-e1f6-42e2-9a07-1ed7832ac6d7","uri":"https://www.hostgator.com.br/","name":"www.hostgator.com.br/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"c88e58dd-4f2f-4e8e-b2da-526c0f2aa84c","sortOrder":0},"sortOrder":0,"tags":[{"id":"5644ab16-c7ca-4ff7-ac95-383343dab77f","name":"MySQL","targetId":"febd2464-e1f6-42e2-9a07-1ed7832ac6d7"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"febd2464-e1f6-42e2-9a07-1ed7832ac6d7"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"febd2464-e1f6-42e2-9a07-1ed7832ac6d7"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"febd2464-e1f6-42e2-9a07-1ed7832ac6d7"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"febd2464-e1f6-42e2-9a07-1ed7832ac6d7"}],"recentChangeFlags":null},{"id":"7b35000b-fdcc-451b-a221-48416ecc69ff","uri":"https://financeiro.hostgator.com.br","name":"https://financeiro.hostgator.com.br","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a07bb05d-704c-4831-958b-0d783ba238fe","sortOrder":1},"sortOrder":1,"tags":[{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"7b35000b-fdcc-451b-a221-48416ecc69ff"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"7b35000b-fdcc-451b-a221-48416ecc69ff"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"7b35000b-fdcc-451b-a221-48416ecc69ff"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"7b35000b-fdcc-451b-a221-48416ecc69ff"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"10ae4d41-5658-4103-b6b7-d98e4cee1501","p1MaxCents":250000,"p1MinCents":150000,"p2MaxCents":150000,"p2MinCents":75000,"p3MaxCents":45000,"p3MinCents":25000,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eAt HostGator LATAM, we provide comprehensive web hosting solutions tailored to your business needs. With the purchase of our top-tier hosting services, you receive a free domain and email, along with a full suite of features essential for building and maintaining a successful online presence. Our hosting ensures the reliability, scalability, and security required for growing your business. \u003c/p\u003e\n\n\u003ch3\u003eAny subdomain flows (able to clearly showcase the navigation flow) after user authentication to the below listed targets are also in-scope\u003c/h3\u003e\n\n\u003ch3\u003eNew Focus Area:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eAI Agents Section\u003c/li\u003e\n\u003cli\u003eVPS Features, specifically the AI-related functionality\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":1500,"max":2500},"2":{"min":750,"max":1500},"3":{"min":250,"max":450},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"03d6dc00-ae4d-4f12-948e-9f879e1377ab","name":"Out of Scope","targets":[{"id":"0dc7d65b-5aa5-4185-bdfd-e56183b589ba","uri":"","name":"https://carrinho.hostgator.com.br/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b660100a-b558-4d15-8680-076766ce0019","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null},{"id":"681d9c75-f28b-4266-9b88-a8a9782e4f1c","uri":"https://www.academy.hostgator.com","name":"academy.hostgator.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2d60927f-986a-4327-9163-8ce98ce53ba9","sortOrder":2},"sortOrder":2,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"681d9c75-f28b-4266-9b88-a8a9782e4f1c"}],"recentChangeFlags":null},{"id":"22a56a72-203a-4c91-884b-e32a8c4e3992","uri":"https://www.hostgator.com.br","name":"*.hostgator.com.br","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"7ad7461b-e8e0-4519-bcb3-f54bde617177","sortOrder":3},"sortOrder":3,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"22a56a72-203a-4c91-884b-e32a8c4e3992"}],"recentChangeFlags":null},{"id":"5df880a0-45fd-43ee-b7f4-13d1f6a5cb45","uri":"","name":"*.hostgator.mx","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8958627f-8494-4abb-93b3-d507c1a1c45a","sortOrder":3},"sortOrder":3,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"5df880a0-45fd-43ee-b7f4-13d1f6a5cb45"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eAny asset not explicitly listed in scope above falls outside this program. If you have found a vulnerability on an asset not covered here, we still want to hear from you — please submit it through our Vulnerability Disclosure Program using the links below:\u003c/p\u003e\n\n\u003cp\u003e\u003ca href=\"https://www.hostgator.com.br/disclosure\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHostgator LATAM\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003eReports submitted through these links will be reviewed by our security team.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"c4bbb2cf-1b0a-4439-a784-066a18e53e0f","code":"hostgator-latam-bb","state":"in_progress","endsAt":null,"bountyId":"6a29114c-7286-4577-b068-7d33b148c81e","startsAt":"2022-02-01T19:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/746a/65fe/37fbf960/8434d215f5ea8617bcd48b53664d246a_latam.jpeg","logoBackgroundColor":"#f98f48","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2022-02-01T19:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/hostgator-latam-bb","changelogs":"/engagements/hostgator-latam-bb/changelog","submissions":null,"announcements":"/engagements/hostgator-latam-bb/announcements","hallOfFame":"/engagements/hostgator-latam-bb/hall_of_fames","crowdstream":null},"announcementsCount":4,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/hostgator-latam-bb/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=hostgator-latam-bb\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/hostgator-latam-bb/engagement_subscribers","engagementChangelogsUrl":"/engagements/hostgator-latam-bb/changelog","publishedAt":"2026-09-11T15:03:02.310Z","engagementChangelogUrl":"/engagements/hostgator-latam-bb/changelog/e57fb9c2-18c7-4440-891f-d7fd8857088c","createUserFeedbacksUrl":"/engagements/hostgator-latam-bb/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}