{"id":"13ba2a60-317b-4c20-b9bb-e214266d874f","engagementId":"4d7e0e08-bd36-48e2-9a8d-54417b4d0ee0","data":{"brief":{"id":"1a3147ec-7200-438e-8683-0ac196d63055","name":"Kiteworks","tagline":"Help Secure Kiteworks","description":"\u003cp\u003eKiteworks’ mission is to empower organizations to effectively manage risk in every send, share, receive and save of sensitive content. To this end, we created a platform that delivers content governance, compliance, and protection to customers. The platform unifies, tracks, controls, and secures sensitive content moving within, into, and out of their organization, significantly improving risk management and ensuring regulatory compliance on all sensitive content communications.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eImportant information on vulnerabilities that require admin privileges\u003c/h3\u003e\n\n\u003cp\u003eAs Kiteworks is an on-premises enterprise product, it is administered by corporate administrators responsible for the systems and their user base. For that reason, we do not generally consider vulnerabilities that require administrator privileges (CVSS PR:H) for exploitation to be critical. This would mean that we would down-rate such vulnerabilities to a maximum of CVSS 8.9.\u003c/p\u003e\n\n\u003ch3\u003eXSS Reporting Requirements\u003c/h3\u003e\n\n\u003cp\u003ePlease note that for any reports involving Cross-Site Scripting (XSS), a basic proof-of-concept such as a JavaScript alert box (e.g., \u003ccode\u003ealert(1)\u003c/code\u003e) will not be considered sufficient for triage or reward. To qualify for a valid report, you must demonstrate a clear and actionable impact resulting from the XSS vulnerability. This includes, but is not limited to:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePerforming actions on behalf of another user (e.g., creating a new user account or modifying user settings)\u003c/li\u003e\n\u003cli\u003eExfiltrating sensitive data (e.g., sending authentication cookies or session tokens to an external server)\u003c/li\u003e\n\u003cli\u003eBypassing security controls or escalating privileges\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThe goal is to understand the real-world risk and exploitability of the issue, so please ensure your report includes a well-documented and impactful demonstration.\u003c/p\u003e\n\n\u003ch3\u003eSubmission Rating\u003c/h3\u003e\n\n\u003cp\u003eKiteworks adheres to the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e for the prioritization of submissions but reserves the right to downgrade or upgrade ratings based on actual business impact and CVSS score. In the event of a downgrade, Kiteworks will provide a reasonable justification to the researcher - along with the opportunity to appeal and make a case for a higher priority.\u003c/p\u003e\n\n\u003ch4\u003ePlease note\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003e Multiple vulnerabilities caused by one underlying issue will be recognized as one vulnerability. \u003c/li\u003e\n\u003cli\u003e For unauthenticated XSS, it will be treated as a High severity. For authenticated XSS, it will be treated as a Medium severity.\u003c/li\u003e\n\u003c/ul\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Kiteworks not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Kiteworks, you can report it here. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003ch3\u003eAccess:\u003c/h3\u003e\n\n\u003cp\u003e4 User Profiles:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eStandard User\u003c/li\u003e\n\u003cli\u003eRestricted User\u003c/li\u003e\n\u003cli\u003eRecipient User\u003c/li\u003e\n\u003cli\u003eCustom User\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eFor you have been provisioned 1 pseudo-random @bugcrowdninja.com email (for testing access issues between accounts) which, after accepting the program invite, will route all incoming traffic to the email associated with your Bugcrowd account. An invite to the application has been sent to each of these emails in advance, and will be auto-forwarded upon accepting your invitation to the program.\u003c/p\u003e\n\n\u003cp\u003eTo access each user profile, please append a plus (\"+\") sign, with a combination of the user profile to follow after your email address. For example, if your email address was yourusername@bugcrowdninja.com, you could access mail via yourusername+standard@bugcrowdninja.com or yourusername+restricted@bugcrowdninja.com or yourusername+recipient@bugcrowdninja.com or yourusername+custom@bugcrowdninja.com,\u003c/p\u003e\n\n\u003cp\u003eFor more information regarding the exact user profile configurations, please do access the \u003ca href=\"https://bugcrowd.com/kiteworks-public/resources\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eResources tab\u003c/a\u003e.\u003c/p\u003e\n\n\u003cp\u003eTo access the account visit \u003ca href=\"https://kw-bugcrowd-pub.bounty.kiteworks.dev/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://kw-bugcrowd-pub.bounty.kiteworks.dev/\u003c/a\u003e and login with the username structure listed above and  password provided. Upon successfully logging in, you will be redirected to an update password process. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eOut-of-Scope\u003c/h3\u003e\n\u003cdiv class=\"highlight\"\u003e\u003cpre class=\"highlight plaintext\"\u003e\u003ccode\u003e- Any hypothetical flaw or best practices without exploitable POC\n- Any security issues in third-party apps or websites that integrate with Kiteworks or third-party libraries\n- Reports from automated web/mobile vulnerability scanners that have not been validated\n- Reports that state that software is out of date/vulnerable without a proof-of-concept\n- Open ports without an accompanying proof-of-concept demonstrating vulnerability\n- Exposed login panels\n- Reports that affect only outdated devices, browsers or platforms\n- Recently publicly disclosed vulnerabilities\n- Non sensitive information disclosure: stack traces, path disclosure, directory listings, software versions, etc\n- Issues requiring physical access to a user’s computer/device/email/etc\n- Bugs that rely on unlikely or statistically improbable user interaction\n- Vulnerabilities that require privileged user (e.g. root) access\n- Social engineering attempts\n- Credential stuffing\n- Email spoofing and/or missing DMARC records.\n- Brute force attacks that cannot be demonstrated or completed in a reasonable amount of time\n- Enumeration/account oracles: possibility to enumerate phone number, email, GUID, etc. and receive back a message indicating it exists\n- Password and account recovery policies, such as reset link expiration or password complexity\n- SSL/TLS best practices\n- \"HTTP Host Header\" XSS / \"Self\" XSS\n- Text/HTML Injection\n- Logout and other instances of low-severity Cross-Site Request Forgery\n- Cross-Site Request Forgery not exploitable with Chrome \u0026gt; 80\n- Unchained open redirects\n- CSV injection\n- Clickjacking/UI redressing\n- Missing autocomplete attributes\n- Missing cookie flags\n- Missing security-related HTTP headers which do not lead directly to a vulnerability\n- Mixed content warnings\n- Protocol mismatch\n- RTLO and related issues\n- Homograph Attack\n- Denial of Service attacks\n- Rate limiting issues\n- Invalid or missing SPF (Sender Policy Framework) records (Incomplete or missing SPF/DKIM/DMARC)\n- Storing malware/bypassing antivirus detection\n- Bypass of the filetype filter by renaming the file\n- EXIF Geolocation Data Not Stripped From Uploaded Images\n- Domain/Sub-domain take over\n- Race condition\n\u003c/code\u003e\u003c/pre\u003e\u003c/div\u003e\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"partial","label":"Partial safe harbor","description":"This engagement provides a limited goodwill statement about not pursuing legal action related to security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"285e0b61-f9cb-4efc-aa98-c54fc441430e","name":"████████████████","targets":[{"id":"b53e65bf-c6f3-4c2b-ad6c-005e55fe9386","uri":null,"name":"█████████████████████████████████████████████","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"de9830b0-f6f0-48bc-9d13-62d9e79cd1e9","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"b53e65bf-c6f3-4c2b-ad6c-005e55fe9386"},{"id":"041d5363-86a6-40b1-9a02-c20f6ab39c05","name":"Linux","targetId":"b53e65bf-c6f3-4c2b-ad6c-005e55fe9386"},{"id":"a4603de0-3954-4611-9704-cebf3801dbf8","name":"Flask","targetId":"b53e65bf-c6f3-4c2b-ad6c-005e55fe9386"},{"id":"eaa69542-87cd-413a-9b74-3e75f9fb01e4","name":"Angular","targetId":"b53e65bf-c6f3-4c2b-ad6c-005e55fe9386"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"b53e65bf-c6f3-4c2b-ad6c-005e55fe9386"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"b53e65bf-c6f3-4c2b-ad6c-005e55fe9386"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"b53e65bf-c6f3-4c2b-ad6c-005e55fe9386"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"b53e65bf-c6f3-4c2b-ad6c-005e55fe9386"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"b53e65bf-c6f3-4c2b-ad6c-005e55fe9386"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"b53e65bf-c6f3-4c2b-ad6c-005e55fe9386"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"ccf8b070-b9c1-4ab6-9212-1abc09ec05ff","p1MaxCents":2500000,"p1MinCents":1100000,"p2MaxCents":1000000,"p2MinCents":500000,"p3MaxCents":300000,"p3MinCents":60000,"p4MaxCents":50000,"p4MinCents":25000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":5000000},"descriptionHtml":"██████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████","rewardRangeData":{"1":{"min":11000,"max":25000},"2":{"min":5000,"max":10000},"3":{"min":600,"max":3000},"4":{"min":250,"max":500},"5":{"min":null,"max":null},"programMax":50000},"recentChangeFlags":null},{"id":"110b010a-e622-4010-85d4-28309c010a12","name":"████████████","targets":[{"id":"eb0b08bd-dae9-415e-849a-7f8a5e9b4d61","uri":null,"name":"█████████████████████████████████████████","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"22237168-ad89-475b-acd6-25dd8f0a66b6","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"eb0b08bd-dae9-415e-849a-7f8a5e9b4d61"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[{"id":"93e55187-18f6-45d2-916b-1bacf7a9b7af","attachmentPath":"https://bugcrowd.com/engagements/kiteworks-public/attachments/93e55187-18f6-45d2-916b-1bacf7a9b7af","name":"User%20Profile%20Config.pdf","filename":"User%20Profile%20Config.pdf","description":"Current User Profile Configuration via Admin Settings","icon":"fileOther","size":3478395,"sizeLabel":"3.32 MB","uploadedAt":"11 Sep 2024","fileType":"Document","embedUrl":"https://bugcrowd.com/engagements/kiteworks-public/attachments/93e55187-18f6-45d2-916b-1bacf7a9b7af"},{"id":"862c36e1-2991-449c-ba3e-8a961b07a590","attachmentPath":"https://bugcrowd.com/engagements/kiteworks-public/attachments/862c36e1-2991-449c-ba3e-8a961b07a590","name":"Send%20Mail%20Config.pdf","filename":"Send%20Mail%20Config.pdf","description":"Current Send Mail Configuration via Admin settings","icon":"fileOther","size":118888,"sizeLabel":"116 KB","uploadedAt":"11 Sep 2024","fileType":"Document","embedUrl":"https://bugcrowd.com/engagements/kiteworks-public/attachments/862c36e1-2991-449c-ba3e-8a961b07a590"},{"id":"7ed18a82-a437-46b6-845b-cd20664fec22","attachmentPath":"https://bugcrowd.com/engagements/kiteworks-public/attachments/7ed18a82-a437-46b6-845b-cd20664fec22","name":"Files%20and%20Folder%20Rentention%20Config.pdf","filename":"Files%20and%20Folder%20Rentention%20Config.pdf","description":"Current Files and Folder Retention Configuration via Admin Settings","icon":"fileOther","size":151796,"sizeLabel":"148 KB","uploadedAt":"11 Sep 2024","fileType":"Document","embedUrl":"https://bugcrowd.com/engagements/kiteworks-public/attachments/7ed18a82-a437-46b6-845b-cd20664fec22"},{"id":"55a3d2ab-05c0-4468-93f3-05c0e0743ddc","attachmentPath":"https://bugcrowd.com/engagements/kiteworks-public/attachments/55a3d2ab-05c0-4468-93f3-05c0e0743ddc","name":"Accellion_lookout.pdf","filename":"Accellion_lookout.pdf","description":null,"icon":"fileOther","size":92870,"sizeLabel":"90.7 KB","uploadedAt":"11 Sep 2024","fileType":"Document","embedUrl":"https://bugcrowd.com/engagements/kiteworks-public/attachments/55a3d2ab-05c0-4468-93f3-05c0e0743ddc"}],"engagement":{"id":"4d7e0e08-bd36-48e2-9a8d-54417b4d0ee0","code":"kiteworks-public","state":"in_progress_paused","endsAt":null,"bountyId":"02b566ab-3cea-40e8-b176-b41c9ba62ef5","startsAt":"2020-10-08T17:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/90dc/0075/3122fe27/daa4fee45a4ea7adea7f6a39506750a4_kiteworks-primary-white-coloured-bg-icon-01__1_.jpg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":"We are closing this program.\n\nEffective immediately, the program is no longer accepting new\nsubmissions.\n\nEvery report already submitted will be handled in full. We will triage\nand validate each one, take it through to a final state, and pay\nrewards under the existing reward grid. Nothing already in the queue is\naffected by this closure.\n\nTo report a vulnerability from this point on, please use our\nVulnerability Disclosure Program at https://security.kiteworks.com,\nwhich sets out our current disclosure policy and reporting channels\nacross our products.\n\nThank you to everyone who contributed research here. The findings from\nthis program led to real fixes in our products, and we appreciate the\ntime you put into it.\n\nKind regards,\nKiteworks Security Team","lastTransitionAt":"2026-09-11T07:57:59.115Z","cancellationReason":null,"statusLabel":"In progress paused","routesPaths":{"brief":"/engagements/kiteworks-public","changelogs":"/engagements/kiteworks-public/changelog","submissions":null,"announcements":"/engagements/kiteworks-public/announcements","hallOfFame":"/engagements/kiteworks-public/hall_of_fames","crowdstream":"/engagements/kiteworks-public/crowdstream"},"announcementsCount":15,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"P1 24/7","submitReportUrl":null,"methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=kiteworks-public\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/kiteworks-public/engagement_subscribers","engagementChangelogsUrl":"/engagements/kiteworks-public/changelog","publishedAt":"2026-09-11T07:57:59.144Z","engagementChangelogUrl":"/engagements/kiteworks-public/changelog/13ba2a60-317b-4c20-b9bb-e214266d874f","createUserFeedbacksUrl":"/engagements/kiteworks-public/feedbacks","engagementCrowdstreamUrl":"/engagements/kiteworks-public/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}