{"id":"c321ca42-ab54-4b40-8f62-939fa6cc82dc","engagementId":"9152e59e-bfb7-43a6-b259-24f7a119684e","data":{"brief":{"id":"9ae42b09-e893-489c-b62a-8b8c68220005","name":"The Hut Group: Public Managed Bug Bounty Engagement","tagline":"The Hut Group Bug Bounty Program","description":"\u003cp\u003eNo technology is perfect and The Hut Group believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our web applications, mobile applications and APIs. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"9ed1ce49-a148-438f-92d3-0b8d70b6a8ae","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of The Hut Group not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to The Hut Group, please reach out to \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e. We will address your issue as soon as possible.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eTargets\u003c/h2\u003e\n\n\u003cp\u003eThe targets are on several shared platforms. Submissions on a target will be likely valid for other targets on the platform that they share. Any vulnerabilities submitted on a shared platform will be duplicated against the first submission that was made. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch1\u003eRules\u003c/h1\u003e\n\n\u003cul\u003e\n\u003cli\u003eDo not access customer or employee personal information or confidential information belonging to The Hut Group. If you accidentally access any of these, please stop testing and submit the vulnerability.\u003c/li\u003e\n\u003cli\u003eIf you believe you have found sensitive customer data such as login credentials, API keys etc., or a way to access customer data through a vulnerability then report it, but do not attempt to successfully validate it works.\u003c/li\u003e\n\u003cli\u003eIf you accidently access sensitive data belonging to customers, employees or The Hut Group, please destroy the data securely and report the details of how this data was obtained.\u003c/li\u003e\n\u003cli\u003eCollect only the information necessary to demonstrate the vulnerability.\u003c/li\u003e\n\u003cli\u003eWhen investigating a vulnerability, please only target your own test accounts and do not attempt to access data from anyone else’s account.\u003c/li\u003e\n\u003cli\u003eBounties are given at the discretion of The Hut Group and we withhold the right to modify or deny bounties. We can assure all researchers this will be done fairly. \u003c/li\u003e\n\u003cli\u003eDo NOT conduct attacks such as social engineering, phishing or unauthorized access to infrastructure.\u003c/li\u003e\n\u003cli\u003eDo NOT test the physical security of The Hut Group offices, employees, equipment, etc.\u003c/li\u003e\n\u003cli\u003ePlease use a sensible rate limit when running automated scanners, we consider around 5 requests per second sensible. \u003c/li\u003e\n\u003cli\u003ePlease include the following headers in all server requests. This allows us to identify researcher testing activity and avoids blocking. \n\n\u003cul\u003e\n\u003cli\u003eX-Request-ID: Bugcrowd\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eVulnerability reports which do not include manual validation with a proof of concept will be closed as Not Applicable.\u003c/li\u003e\n\u003cli\u003eWhen duplicates occur, we only award the first report that was received.\u003c/li\u003e\n\u003cli\u003eMultiple vulnerabilities caused by one underlying issue will be awarded one bounty.\u003c/li\u003e\n\u003cli\u003eMultiple similar vulnerabilities against 1 target may be considered as one higher severity “Site-Wide” issue, for example multiple instances of privilege escalation using 1 specific user role on 1 site within scope.\u003c/li\u003e\n\u003cli\u003eBe mindful with the rate and scope of automated scanning tools. \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch1\u003eSubmissions\u003c/h1\u003e\n\n\u003cp\u003e\u003cstrong\u003ePlease be descriptive in your submission's titles and descriptions. Give detailed proofs of concept with actual attack scenarios.\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch3\u003eCredentials:\u003c/h3\u003e\n\n\u003cp\u003eTo gain access to the applications, please sign up for accounts using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://researcherdocs.bugcrowd.com/v2.0/docs/your-bugcrowdninja-email-address\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003eFocus Areas:\u003c/h2\u003e\n\n\u003cp\u003eWe encourage researchers to focus their efforts in the following areas:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eExfiltration of Sensitive or Personal Data (Employees and Customers) - When testing for customer data exfiltration, please only use accounts that you own. Do not test on customer data.\u003c/li\u003e\n\u003cli\u003eBusiness Logic Flaws.\u003c/li\u003e\n\u003cli\u003eRemote Code Execution.\u003c/li\u003e\n\u003cli\u003eSQL and Command Injection.\u003c/li\u003e\n\u003cli\u003eAuthentication Bypass.\u003c/li\u003e\n\u003cli\u003eCross Site Scripting (XSS).\u003c/li\u003e\n\u003cli\u003eCross Site Request Forgery (CSRF).\u003c/li\u003e\n\u003cli\u003eInsecure Direct Object References.\u003c/li\u003e\n\u003cli\u003ePrivilege Escalation.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eExcluded from Rewards\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eOAUTH pre account take over is a known issue and currently out of scope until further notice.\u003c/li\u003e\n\u003cli\u003ePhysical testing.\u003c/li\u003e\n\u003cli\u003eSocial engineering.\u003c/li\u003e\n\u003cli\u003eDenial of Service attacks.\u003c/li\u003e\n\u003cli\u003eSubdomain Takeover.\u003c/li\u003e\n\u003cli\u003eContent spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS.\u003c/li\u003e\n\u003cli\u003eRate limiting or brute force issues on non-authentication endpoints. On authentication endpoints, THG will determine what is considered acceptable rate limiting. \u003c/li\u003e\n\u003cli\u003eBrute forcing of any accounts not owned by yourself. \u003c/li\u003e\n\u003cli\u003eMail Server Domain Misconfiguration (including email spoofing, missing DMARC, SPF/DKIM/DMARC, etc.)\u003c/li\u003e\n\u003cli\u003eInternal IP address disclosure.\u003c/li\u003e\n\u003cli\u003eMissing best practices in Content Security Policy.\u003c/li\u003e\n\u003cli\u003eWeak password policies.\u003c/li\u003e\n\u003cli\u003ePresence of application or web browser ‘autocomplete’ or ‘save password’ functionality.\u003c/li\u003e\n\u003cli\u003eLack of Secure/HTTPOnly flags on non-sensitive Cookies.\u003c/li\u003e\n\u003cli\u003eSelf-XSS.\u003c/li\u003e\n\u003cli\u003eVulnerabilities that are limited to unsupported browsers will not be accepted (i.e. \"this exploit only works in IE6/IE7\").\u003c/li\u003e\n\u003cli\u003eKnown vulnerabilities in used libraries unless you can prove exploitability.\u003c/li\u003e\n\u003cli\u003eReports directly from automated tools or scans without a manual Proof of Concept.\u003c/li\u003e\n\u003cli\u003eReports of insecure SSL/TLS ciphers without a working proof of concept.\u003c/li\u003e\n\u003cli\u003eSocial Media Account (Twitter/LinkedIn/Facebook etc.) hijacking via a broken link.\u003c/li\u003e\n\u003cli\u003eOut-of-date software without known vulnerabilities.\u003c/li\u003e\n\u003cli\u003eUse of a known-vulnerable component unless you are able to provide proof of exploitation.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"b1e5b555-8b11-4fb9-8758-54424964e702","name":"Ingenuity E-Commerce","targets":[{"id":"50ba8df8-b697-45fb-8739-93bf7e22c40b","uri":"https://www.cultbeauty.co.uk/","name":"https://*.cultbeauty.co.uk/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"03b0db87-6d32-4f6e-be38-df3223699bd7","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"50ba8df8-b697-45fb-8739-93bf7e22c40b"},{"id":"9558d6b3-9880-4506-9e19-55dc1d7d8aff","name":"RequireJS","targetId":"50ba8df8-b697-45fb-8739-93bf7e22c40b"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"50ba8df8-b697-45fb-8739-93bf7e22c40b"}],"recentChangeFlags":null},{"id":"f54b78ab-d0a4-428a-bf56-07e263be9f1a","uri":"https://www.lookfantastic.com/","name":"https://*.lookfantastic.com/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"1b28c4f2-d2db-4171-8a3f-ad9cb00441b5","sortOrder":1},"sortOrder":1,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"f54b78ab-d0a4-428a-bf56-07e263be9f1a"},{"id":"9558d6b3-9880-4506-9e19-55dc1d7d8aff","name":"RequireJS","targetId":"f54b78ab-d0a4-428a-bf56-07e263be9f1a"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"f54b78ab-d0a4-428a-bf56-07e263be9f1a"}],"recentChangeFlags":null},{"id":"35852a6a-724b-4746-bc32-1e16bff7491b","uri":"https://www.myprotein.com/","name":"https://*.myprotein.com/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"123d0f3c-960d-4daf-8d1c-5a5d40d36be6","sortOrder":2},"sortOrder":2,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"35852a6a-724b-4746-bc32-1e16bff7491b"},{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"35852a6a-724b-4746-bc32-1e16bff7491b"},{"id":"9558d6b3-9880-4506-9e19-55dc1d7d8aff","name":"RequireJS","targetId":"35852a6a-724b-4746-bc32-1e16bff7491b"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"35852a6a-724b-4746-bc32-1e16bff7491b"}],"recentChangeFlags":null},{"id":"847ff764-8fca-4713-a657-94e704c8de5d","uri":"https://www.myvitamins.com/","name":"https://*.myvitamins.com/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"2cf241f0-d248-4407-bfdc-ee21e6ee4ebd","sortOrder":3},"sortOrder":3,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"847ff764-8fca-4713-a657-94e704c8de5d"},{"id":"9558d6b3-9880-4506-9e19-55dc1d7d8aff","name":"RequireJS","targetId":"847ff764-8fca-4713-a657-94e704c8de5d"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"847ff764-8fca-4713-a657-94e704c8de5d"}],"recentChangeFlags":null},{"id":"5e9209d4-8ee4-4cb3-8c76-3c5e7fe5931a","uri":"https://www.arrowfilms.com","name":"https://*.arrowfilms.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f2508964-9271-4c88-980b-0b6cace0370d","sortOrder":4},"sortOrder":4,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"5e9209d4-8ee4-4cb3-8c76-3c5e7fe5931a"},{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"5e9209d4-8ee4-4cb3-8c76-3c5e7fe5931a"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"5e9209d4-8ee4-4cb3-8c76-3c5e7fe5931a"}],"recentChangeFlags":null},{"id":"10381143-d42e-4bda-a194-c30df01e927c","uri":"https://www.mankind.co.uk/","name":"https://*.mankind.co.uk/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"fbc58635-bfe3-4e96-a877-6001befd9eb5","sortOrder":5},"sortOrder":5,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"10381143-d42e-4bda-a194-c30df01e927c"},{"id":"9558d6b3-9880-4506-9e19-55dc1d7d8aff","name":"RequireJS","targetId":"10381143-d42e-4bda-a194-c30df01e927c"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"10381143-d42e-4bda-a194-c30df01e927c"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"10381143-d42e-4bda-a194-c30df01e927c"}],"recentChangeFlags":null},{"id":"5f03c23e-9ac8-4455-b884-e8273ecb164b","uri":"https://www.illamasqua.com/","name":"https://*.illamasqua.com/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"41197056-e270-4620-8b52-e73672c146c1","sortOrder":6},"sortOrder":6,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"5f03c23e-9ac8-4455-b884-e8273ecb164b"},{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"5f03c23e-9ac8-4455-b884-e8273ecb164b"},{"id":"9558d6b3-9880-4506-9e19-55dc1d7d8aff","name":"RequireJS","targetId":"5f03c23e-9ac8-4455-b884-e8273ecb164b"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"5f03c23e-9ac8-4455-b884-e8273ecb164b"}],"recentChangeFlags":null},{"id":"e41f9645-64da-46ad-832b-17d783b870d8","uri":"https://www.matalan.co.uk","name":"https://www.matalan.co.uk","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"bd1ae1e7-f432-464e-bea2-ac365a5e2f2b","sortOrder":7},"sortOrder":7,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"e41f9645-64da-46ad-832b-17d783b870d8"},{"id":"9558d6b3-9880-4506-9e19-55dc1d7d8aff","name":"RequireJS","targetId":"e41f9645-64da-46ad-832b-17d783b870d8"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"e41f9645-64da-46ad-832b-17d783b870d8"}],"recentChangeFlags":null},{"id":"845508f1-f15b-4e07-9e8f-33a77c8b31a2","uri":"https://www.enjoyselfish.com","name":"https://*.enjoyselfish.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"4c41661d-b9dd-4847-ba44-6d6ede8f3999","sortOrder":8},"sortOrder":8,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"845508f1-f15b-4e07-9e8f-33a77c8b31a2"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"9bf3b0e7-7cc0-46ec-81f6-553cec619379","p1MaxCents":250000,"p1MinCents":200000,"p2MaxCents":150000,"p2MinCents":100000,"p3MaxCents":75000,"p3MinCents":25000,"p4MaxCents":20000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eTargets in this group are sharing the same platform, any valid submissions made will be duplicated against the first submission that was made. \u003c/p\u003e","rewardRangeData":{"1":{"min":2000,"max":2500},"2":{"min":1000,"max":1500},"3":{"min":250,"max":750},"4":{"min":100,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"d1ac01c0-3ec6-4cb1-aee9-3be1e5cc1116","name":"Out of Scope","targets":[{"id":"6c1b83e2-697f-440c-8242-b1ffbac33c22","uri":null,"name":"https://www.myprotein.com.tr/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"dceb6164-e827-47d9-8395-4c932e515463","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"6c1b83e2-697f-440c-8242-b1ffbac33c22"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":5,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"9152e59e-bfb7-43a6-b259-24f7a119684e","code":"hutgroup-public","state":"in_progress","endsAt":null,"bountyId":"3e9b599e-4996-4170-8e62-625434813b0a","startsAt":"2024-09-25T10:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Retail","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/4101/fb5d/666c82db/e5c325738941bdaf9cf74a6ba90761b7_THG.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2024-09-25T10:00:00.022Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/hutgroup-public","changelogs":"/engagements/hutgroup-public/changelog","submissions":null,"announcements":"/engagements/hutgroup-public/announcements","hallOfFame":"/engagements/hutgroup-public/hall_of_fames","crowdstream":"/engagements/hutgroup-public/crowdstream"},"announcementsCount":10,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/hutgroup-public/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=hutgroup-public\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/hutgroup-public/engagement_subscribers","engagementChangelogsUrl":"/engagements/hutgroup-public/changelog","publishedAt":"2026-01-06T11:44:00.554Z","engagementChangelogUrl":"/engagements/hutgroup-public/changelog/c321ca42-ab54-4b40-8f62-939fa6cc82dc","createUserFeedbacksUrl":"/engagements/hutgroup-public/feedbacks","engagementCrowdstreamUrl":"/engagements/hutgroup-public/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}