{"id":"7e042a71-9e70-41a7-a74a-a8be492b7e5a","engagementId":"fa60a2c0-e783-4f10-8122-50bfdbd14b99","data":{"brief":{"id":"e7c78516-3630-4531-8274-e191ff6137d3","name":"Zoopla Vulnerability Disclosure Engagement","tagline":"Creating the connections that power better property decisions","description":"\u003cp\u003eCreating the connections that power better property decisions\u003c/p\u003e\n\n\u003cp\u003eOur software solutions connect businesses and consumers, powering more than half of all UK housing transactions each year.\u003c/p\u003e\n\n\u003cp\u003eWe deliver a one-stop shop for estate agents and home builders to drive efficiencies, speed up the transaction while reducing risk, improve end-customer experiences, stay ahead of regulatory changes and unlock new areas for business growth.\u003c/p\u003e\n\n\u003cp\u003eOur open APIs integrate with other platforms across lending, conveyancing and prop-tech providers, enabling us to power end-to-end property transactions and unlock a wide range of benefits for the wider industry and their customers.\u003c/p\u003e\n\n\u003cp\u003eAt Houseful we take the security of our systems seriously, and we value the security researcher community. The disclosure of security vulnerabilities by security researchers helps us ensure the security and privacy of our users.\u003c/p\u003e\n\n\u003ch2\u003eGuidelines\u003c/h2\u003e\n\n\u003cp\u003eWe require that all researchers:\u003c/p\u003e\n\n\u003cp\u003e• Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction of data during security testing; Perform research only within the scope set out below;\u003cbr\u003e\n• Use the identified communication channels to report vulnerability information to us; and\u003cbr\u003e\n• Keep information about any vulnerabilities you’ve discovered confidential between yourself and Houseful until we’ve had 90 days to resolve the issue.\u003c/p\u003e\n\n\u003cp\u003eIf you follow these guidelines when reporting an issue to us we commit to:\u003cbr\u003e\n• Not institute a civil legal action against you and not support a criminal investigation;\u003cbr\u003e\n• Work with you to understand and resolve the issue quickly (confirming the report within 72 hours of submission);\u003cbr\u003e\n• Recognize your contribution on our Security Researcher Hall of Fame, if you are the first to report the issue and we make a code or configuration change based on the issue.\u003cbr\u003e\nThank you for participating, it is your work that will help to keep us secure.\u003cbr\u003e\nThis program only awards points for VRT based submissions.\u003c/p\u003e\n\n\u003ch2\u003eOut of scope\u003c/h2\u003e\n\n\u003cp\u003eAny services hosted by 3rd party providers and services are excluded from scope.\u003cbr\u003e\nIn the interest of the safety of our users, staff, the Internet at large and you as the security researcher, the following test types are excluded from scope and not eligible for a reward:\u003cbr\u003e\n• All submissions matching P5 in Bugcrowd's Vulnerability Rating Taxonomy will be marked Wont Fix\u003cbr\u003e\n• Findings from physical testing such as office access (e.g. open doors, tailgating)\u003cbr\u003e\n• Findings derived primarily from social engineering (e.g. phishing, vishing)\u003cbr\u003e\n• Findings from applications or systems not listed in the ‘Targets’ section\u003cbr\u003e\n• Functional, UI and UX bugs and spelling mistakes\u003cbr\u003e\n• Network level Denial of Service (DoS/DDoS) vulnerabilities\u003c/p\u003e\n\n\u003cp\u003eThings we do not want to see:\u003cbr\u003e\n• Personally identifiable information of users (PII) that you may have found during your research\u003cbr\u003e\nResponsible Disclosure Guidelines:\u003cbr\u003e\nWe will investigate legitimate reports and make every effort to correct any valid vulnerability as quickly as possible. In the spirit of encouraging responsible disclosure and reporting, we will not take legal action against nor ask law enforcement to investigate researchers participating in the program provided their compliance with the following Responsible Disclosure Guidelines:\u003cbr\u003e\n• Provide full details of the vulnerability, including information needed to reproduce and validate the issue by producing\u003cbr\u003e\n• Proof of Concept (code, technical demos of vulnerability, or necessary steps needed to demonstrate your finding)\u003cbr\u003e\n• Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services\u003cbr\u003e\n• Do not modify, access, or retain data that does not belong to you\u003cbr\u003e\n• Do not disclose any vulnerabilities or their technical details without written permission from Express Scripts\u003c/p\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003cbr\u003e\n• Authorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003cbr\u003e\n• Exempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003cbr\u003e\n• Exempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy;\u003cbr\u003e\n• Lawful, helpful to the overall security of the Internet, and conducted in good faith.\u003cbr\u003e\nYou are expected, as always, to comply with all applicable laws.\u003cbr\u003e\nIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our official channels before going any further.\u003c/p\u003e\n\n\u003ch2\u003eOut of scope\u003c/h2\u003e\n\n\u003cp\u003eAny services hosted by 3rd party providers and services are excluded from scope. \u003c/p\u003e\n\n\u003cp\u003eIn the interest of the safety of our users, staff, the Internet at large and you as the security researcher, the following test types are excluded from scope and not eligible for a reward:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAll submissions matching P5 in Bugcrowd's Vulnerability Rating Taxonomy will be marked Wont Fix\u003c/li\u003e\n\u003cli\u003eFindings from physical testing such as office access (e.g. open doors, tailgating)\u003c/li\u003e\n\u003cli\u003eFindings derived primarily from social engineering (e.g. phishing, vishing)\u003c/li\u003e\n\u003cli\u003eFindings from applications or systems not listed in the ‘Targets’ section\u003c/li\u003e\n\u003cli\u003eFunctional, UI and UX bugs and spelling mistakes\u003c/li\u003e\n\u003cli\u003eNetwork level Denial of Service (DoS/DDoS) vulnerabilities\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThings we do not want to see:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePersonally identifiable information of users (PII) that you may have found during your research\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eResponsible Disclosure Guidelines:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eWe will investigate legitimate reports and make every effort to correct any valid vulnerability as quickly as possible. In the spirit of encouraging responsible disclosure and reporting, we will not take legal action against nor ask law enforcement to investigate researchers participating in the program provided their compliance with the following Responsible Disclosure Guidelines:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eProvide full details of the vulnerability, including information needed to reproduce and validate the issue by producing \u003c/li\u003e\n\u003cli\u003eProof of Concept (code, technical demos of vulnerability, or necessary steps needed to demonstrate your finding)\u003c/li\u003e\n\u003cli\u003eMake a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services\u003c/li\u003e\n\u003cli\u003eDo not modify, access, or retain data that does not belong to you\u003c/li\u003e\n\u003cli\u003eDo not disclose any vulnerabilities or their technical details without written permission from Express Scripts\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch1\u003eSafe Harbor\u003c/h1\u003e\n\n\u003cp\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy; \u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls; \u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy;\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eYou are expected, as always, to comply with all applicable laws.\u003c/p\u003e\n\n\u003cp\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our official channels before going any further.\u003c/p\u003e","industryTagId":"f7d6118f-e788-4bb7-a2a6-7078424c9d3c","targetsOverview":"\u003ch3\u003eAccess \u0026amp; Credentials\u003c/h3\u003e\n\n\u003cp\u003eAll of the below targets are publicly accessible. Accounts can be provisioned where signup is available. \u003cbr\u003e\nPlease sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch3\u003eFocus Areas\u003c/h3\u003e\n\n\u003cp\u003eWhile there's no specific main focus at the moment, it would be beneficial to take a closer look at authentication.\u003c/p\u003e\n\n\u003ch3\u003eOut Of Scope\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eAnything not listed in the in scope group\u003c/li\u003e\n\u003cli\u003eAny of our support or contact forms\u003c/li\u003e\n\u003cli\u003eDNS, DNSSEC, HSTS, and DMARC misconfigurations\u003c/li\u003e\n\u003cli\u003eUser data that does not belong to accounts that you have created or been provided\u003c/li\u003e\n\u003cli\u003eAny sort of Denial of Service based attacks\u003c/li\u003e\n\u003cli\u003ePhishing attacks\u003c/li\u003e\n\u003cli\u003eSocial engineering attacks\u003c/li\u003e\n\u003cli\u003eReflected file download\u003c/li\u003e\n\u003cli\u003eSoftware version disclosure\u003c/li\u003e\n\u003cli\u003eIssues requiring direct physical access\u003c/li\u003e\n\u003cli\u003eFlaws affecting out-of-date browsers and plugins\u003c/li\u003e\n\u003cli\u003eCSV injection\u003c/li\u003e\n\u003cli\u003eEmail enumeration / account oracles that do not provide any extra information.\u003c/li\u003e\n\u003cli\u003eCSP Weaknesses\u003c/li\u003e\n\u003cli\u003eEmail Spoofing\u003c/li\u003e\n\u003cli\u003eTechniques allowing you to view other users data\u003c/li\u003e\n\u003cli\u003eBroken links or unclaimed social media accounts (unless chained with an impactful exploit)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eN-Day Policy:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen N-Day bugs are released to the public, we will consider these as in scope after 14 days has gone by\n\n\u003cul\u003e\n\u003cli\u003ee.g: N-day released on 01/01/2025, we would consider it in-scope on 01/15/2025\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"7a0fd04a-c054-4b85-899d-12dbb0b196d8","name":"In Scope Targets","targets":[{"id":"02c6b14f-514a-40e3-abc3-3ec0570ced6c","uri":"https://www.zoopla.co.uk/","name":"Zoopla Web App","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8ef5e022-b376-4a84-897a-5f209d8972e4","sortOrder":0},"sortOrder":0,"tags":[{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"02c6b14f-514a-40e3-abc3-3ec0570ced6c"},{"id":"9ed6a00f-33b7-46f5-add4-2277bd2bea13","name":"Perl","targetId":"02c6b14f-514a-40e3-abc3-3ec0570ced6c"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"02c6b14f-514a-40e3-abc3-3ec0570ced6c"}],"recentChangeFlags":null},{"id":"01bb81ec-8291-4eca-989e-162e8b3b89d7","uri":"https://api-graphql-lambda.prod.zoopla.co.uk/graphql ","name":"Zoopla GraphQL Service","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"c728e087-ec4f-4967-a35c-d76d1eb23f44","sortOrder":1},"sortOrder":1,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"01bb81ec-8291-4eca-989e-162e8b3b89d7"},{"id":"4aeb1677-ac84-4afd-827e-054b363ca984","name":"GraphQL","targetId":"01bb81ec-8291-4eca-989e-162e8b3b89d7"}],"recentChangeFlags":null},{"id":"0922f460-ea23-4299-9238-b50953d4236b","uri":"https://cdn.prod.zoopla.co.uk","name":"Zoopla CDN Service","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f4bcccc9-1f2f-4182-a2f6-dfece3b3817f","sortOrder":2},"sortOrder":2,"tags":null,"recentChangeFlags":null},{"id":"098ead5a-7745-4bc2-8c6d-cd69f2a70d1a","uri":"https://apps.apple.com/gb/app/zoopla-property-search-uk/id380932800","name":"Zoopla IOS App","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f52d2970-83e0-42d5-ae04-6948a767e25b","sortOrder":3},"sortOrder":3,"tags":[{"id":"7cbdff60-9a91-41df-b802-486d21021b34","name":"ReactNative","targetId":"098ead5a-7745-4bc2-8c6d-cd69f2a70d1a"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"098ead5a-7745-4bc2-8c6d-cd69f2a70d1a"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"098ead5a-7745-4bc2-8c6d-cd69f2a70d1a"}],"recentChangeFlags":null},{"id":"dccedacd-174f-4071-91b6-6e1c52607d21","uri":"https://play.google.com/store/apps/details?id=com.zoopla.activity\u0026hl=en_GB\u0026pli=1","name":"Zoopla Android App","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"8ae25632-bc3e-4ddd-b7a3-e83d6fa5d040","sortOrder":4},"sortOrder":4,"tags":[{"id":"7cbdff60-9a91-41df-b802-486d21021b34","name":"ReactNative","targetId":"dccedacd-174f-4071-91b6-6e1c52607d21"},{"id":"8b23fd68-6a22-4028-ad40-652ed6221151","name":"jQuery Mobile","targetId":"dccedacd-174f-4071-91b6-6e1c52607d21"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"dccedacd-174f-4071-91b6-6e1c52607d21"}],"recentChangeFlags":null},{"id":"1463211d-6568-4c53-9d76-96b425b87b71","uri":"https://www.primelocation.com/for-sale/","name":"PrimeLocation","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"6f6278a4-0142-4bf6-a344-80f50c3c6319","sortOrder":5},"sortOrder":5,"tags":[{"id":"4aeb1677-ac84-4afd-827e-054b363ca984","name":"GraphQL","targetId":"1463211d-6568-4c53-9d76-96b425b87b71"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"1463211d-6568-4c53-9d76-96b425b87b71"},{"id":"9ed6a00f-33b7-46f5-add4-2277bd2bea13","name":"Perl","targetId":"1463211d-6568-4c53-9d76-96b425b87b71"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003ch1\u003eTarget information\u003c/h1\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eZoopla Web App\u003c/h2\u003e\n\n\u003cp\u003eZoopla is a property search and real estate marketing platform. Users can access various property-related services through this site, but no authentication is required for basic browsing. The application is primarily built with ReactJS and is hosted on AWS using Linux-based servers.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eZoopla IOS and Android App\u003c/h2\u003e\n\n\u003cp\u003eSame as our Web App\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003ePrimeLocation\u003c/h2\u003e\n\n\u003cp\u003ePrimeLocation is a property search and real estate marketing platform. Users can access various property-related services through this site, but no authentication is required for basic browsing. The application is primarily built with ReactJS and is hosted on AWS using Linux-based servers.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"fa60a2c0-e783-4f10-8122-50bfdbd14b99","code":"houseful-zoopla-vdp","state":"in_progress","endsAt":null,"bountyId":"e56a9b83-048f-416c-9d89-bc363815a4ed","startsAt":"2024-09-05T12:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Real Estate","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/25c2/a378/6d57acc3/4eac20565fcf15f8827ceda12021e385_zoopla_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2024-09-05T12:00:00.230Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/houseful-zoopla-vdp","changelogs":"/engagements/houseful-zoopla-vdp/changelog","submissions":null,"announcements":"/engagements/houseful-zoopla-vdp/announcements","hallOfFame":"/engagements/houseful-zoopla-vdp/hall_of_fames","crowdstream":"/engagements/houseful-zoopla-vdp/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/houseful-zoopla-vdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=houseful-zoopla-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/houseful-zoopla-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/houseful-zoopla-vdp/changelog","publishedAt":"2024-09-05T12:00:00.274Z","engagementChangelogUrl":"/engagements/houseful-zoopla-vdp/changelog/7e042a71-9e70-41a7-a74a-a8be492b7e5a","createUserFeedbacksUrl":"/engagements/houseful-zoopla-vdp/feedbacks","engagementCrowdstreamUrl":"/engagements/houseful-zoopla-vdp/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}