{"id":"b409de16-0a3b-4cad-9292-92582ced5b2f","engagementId":"cb45ce76-8daa-4a4f-ae32-44ca62e4388a","data":{"brief":{"id":"65ab7361-7ba7-4c3b-be20-eb1da7772089","name":"Lightspeed Hospitality","tagline":"Partner with the Lightspeed Security Team to pressure-test and secure the next generation of global hospitality and point-of-sale technology.","description":"\u003ch2\u003eIntroduction\u003c/h2\u003e\n\n\u003cp\u003eWelcome to Lightspeed Hospitality. Help us fortify and pressure-test the scalable point-of-sale engines, tableside ordering pipelines, guest management systems, and back-office orchestration layers driving hospitality merchants worldwide. The Lightspeed Bug Bounty Program is a cornerstone of our commitment to platform resilience, and we actively value collaboration with the global security research community to harden our ecosystem.\u003c/p\u003e\n\n\u003cp\u003eThis page is designed exclusively for security researchers. For general information regarding our corporate security practices, please visit our \u003ca href=\"https://www.lightspeedhq.com/security/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eMain Security Portal\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003ePublic Disclosure Policy\u003c/h2\u003e\n\n\u003cp\u003eThis program operates under a strict Coordinated Disclosure model. To protect the transactional integrity of our hospitality venues and guests, you must not discuss, publish, or leak any vulnerabilities (including fully remediated or closed findings) outside of this program without explicit, prior written consent from the Lightspeed Security Team. \u003c/p\u003e\n\n\u003cp\u003eFailure to comply with these boundaries constitutes a severe policy violation and will result in immediate program disqualification and potential legal escalation. This program adheres fundamentally to \u003ca href=\"https://www.bugcrowd.com/resources/hacker-resources/standard-disclosure-terms/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd’s Standard Disclosure Terms\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003eRatings and Rewards Policy\u003c/h2\u003e\n\n\u003cp\u003eFor the initial prioritization and rating of findings, this program utilizes the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy (VRT)\u003c/a\u003e. \u003c/p\u003e\n\n\u003cblockquote\u003e\n\u003cp\u003e💡 \u003cstrong\u003eTriage Transparency:\u003c/strong\u003e In certain cases, a vulnerability's priority level may be modified due to its real-world likelihood or unique architectural business impact. In any instance where an issue is downgraded, a full, detailed technical explanation will be provided to the researcher—along with an open opportunity to appeal the ticket and present a technical case for a higher priority level.\u003c/p\u003e\n\u003c/blockquote\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eTesting Rules of Engagement\u003c/h2\u003e\n\n\u003cp\u003eTo protect the integrity of our staging infrastructure and avoid accidental IP blocks by our automated defense systems, \u003cstrong\u003eall testing traffic must be clearly identifiable\u003c/strong\u003e.\u003c/p\u003e\n\n\u003ch3\u003e1. Unauthenticated Testing Guardrails\u003c/h3\u003e\n\n\u003cp\u003eUnauthenticated testing must focus on publicly exposed endpoints, login gateways, and public APIs to identify logical flaws, injection vectors, or authentication bypasses. \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eTraffic Attribution (Mandatory):\u003c/strong\u003e Because these tests are performed without an active user session, researchers \u003cstrong\u003emust\u003c/strong\u003e append a custom header to all HTTP traffic containing their unique Bugcrowd identifier (e.g., \u003ccode\u003eX-Bugcrowd-Ninja: [Your_Username]\u003c/code\u003e). \u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eInfrastructure Exclusions:\u003c/strong\u003e Generic infrastructure probing, port scanning, banner grabbing, and volume-based network directory brute-forcing are strictly out of scope and will trigger automated blocking.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003e2. Authenticated Testing Guidance\u003c/h3\u003e\n\n\u003cp\u003eAuthenticated testing must focus on deep business logic flaws, multi-tenant boundaries, data isolation, and authorization states within the hospitality management layers. \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eCredentials \u0026amp; Environments:\u003c/strong\u003e These tests must be performed exclusively using the pre-provisioned testing credentials or designated test store environments provided to you at the bottom of this brief. Accessing, interacting with, or modifying data on any live, operational production customer hospitality venues is strictly prohibited.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003ch2\u003eProgram Rules\u003c/h2\u003e\n\n\u003ch3\u003eEligibility\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eInternal Personnel:\u003c/strong\u003e Current employees, contractors, or individuals with a direct professional relationship with our organization are ineligible to participate.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eLegal Compliance:\u003c/strong\u003e Researchers must comply with all applicable local, national, and international laws. Non-compliance results in immediate program disqualification.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eProfile Requirements:\u003c/strong\u003e Only public, viewable, and verifiable Bugcrowd profiles are eligible for participation and rewards.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePlatform Channel:\u003c/strong\u003e All communication and compensation must go directly through Bugcrowd; internal employees cannot bypass this process.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eScope \u0026amp; Target Guidance\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eStrict Target Boundaries:\u003c/strong\u003e Only security vulnerabilities found within explicitly listed domains and applications are in scope. If an asset or subdomain is not listed in the \"In-Scope\" targets section, do not test it without explicit written permission from the Lightspeed Security team.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eData Privacy:\u003c/strong\u003e Personal Identifiable Information (PII) or system metadata extraction must be limited to the absolute minimum required to prove impact. If sensitive data is accidentally exposed, stop testing immediately, do not download/cache the information, and submit your report right away.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCredential Leaks \u0026amp; OSINT:\u003c/strong\u003e We welcome submissions regarding exposed customer or employee credentials found via legitimate open-source intelligence (OSINT), such as exposed public repositories or open cloud storage buckets. Valid leaks will be triaged case-by-case based on verified business risk.\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cem\u003eExclusion:\u003c/em\u003e Credentials surfaced via criminal activity (e.g., dark web forum dumps, malware stealer logs) are strictly out of scope and ineligible for rewards.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eStrictly Enforced Testing Restrictions\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eEnvironment Separation:\u003c/strong\u003e Testing must only be conducted against shops you created or via pre-provisioned accounts against the URLs explicitly in scope. Testing against real, live operational venues other than those you control will result in immediate disqualification.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePlatform Integrity:\u003c/strong\u003e Make a good faith effort to avoid privacy violations, data destruction, and interruption or degradation of our services. Only interact with accounts you own or have explicit permission from the account holder to test.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAccount Manipulation Boundaries:\u003c/strong\u003e Do not create or add unauthorized secondary users outside the provided testing frameworks. \u003cstrong\u003eDo not attempt password resets, password modifications, or account lockout brute-forcing on profiles you do not control.\u003c/strong\u003e Violating this rule will result in immediate removal from the program.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eProhibited Actions\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eAny testing that impacts the reliability, availability, or operational uptime of our systems.\u003c/li\u003e\n\u003cli\u003ePhysical security testing of corporate facilities, data centers, corporate offices, or equipment.\u003c/li\u003e\n\u003cli\u003eSocial engineering, phishing, or vishing attacks against employees, merchants, or guests.\u003c/li\u003e\n\u003cli\u003eDenial of Service (DoS) or Distributed Denial of Service (DDoS) attacks.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAutomated Volume Scanning:\u003c/strong\u003e Aggressive automated scanning is strictly prohibited (we run these tools internally—do not deploy them against our infrastructure). Testing must be manual and targeted. High-volume scanning will trigger automated IP blocks.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCorporate Integration Isolation:\u003c/strong\u003e Do not test third-party services and integrations utilized by clients (e.g., \u003ccode\u003esupport.vendhq.com\u003c/code\u003e). Vulnerabilities in third-party dependencies must be reported directly to the responsible platform vendor.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eNegotiation:\u003c/strong\u003e Do not attempt to negotiate our program rules, severity evaluations, or reward decisions.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eReporting \u0026amp; Triage\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eSingle Vulnerability Per Report:\u003c/strong\u003e Submit one vulnerability per report unless multiple bugs must be chained together to demonstrate a functional exploit path.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePlatform Exclusive:\u003c/strong\u003e All findings must be submitted exclusively through Bugcrowd to be eligible for validation and rewards. (Out-of-scope assets demonstrably belonging to Lightspeed may be sent to \u003ccode\u003esecurity@lightspeedhq.com\u003c/code\u003e for non-reward coordination).\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eReport Minimums:\u003c/strong\u003e Reports must include a clear description, vulnerable URL, step-by-step reproduction instructions, and an impact analysis. Minimize the inclusion of unmasked PII or system data in your PoC.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eAwards \u0026amp; Discretion\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eFirst-to-Report:\u003c/strong\u003e In the case of duplicate reports, rewards are granted only to the first reproducible submission received.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eUnderlying Root Cause:\u003c/strong\u003e Multiple vulnerabilities originating from a single underlying systemic issue will receive a single reward tier.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eNo Impact, No Reward:\u003c/strong\u003e Vulnerabilities that do not represent a clear, actionable security risk to the organization will be closed without bounty.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eProgram Discretion:\u003c/strong\u003e We reserve the exclusive right to determine eligibility, severity ratings, and final reward amounts. The program rules may be modified or terminated at any time without prior notice.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAreas of Particular Interest\u003c/h2\u003e\n\n\u003cp\u003eWe prioritize findings that expose severe backend logic flaws, isolation boundary collapses, or direct server-side compromise.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eCross-Tenant Access Control \u0026amp; IDORs:\u003c/strong\u003e Broken Object Level Authorization (BOLA) or privilege escalation flaws that allow a user from one merchant organization to view, modify, or delete data belonging to a completely separate merchant organization.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eVertical Privilege Escalation:\u003c/strong\u003e Bypassing role-based access controls (RBAC) within a venue environment (e.g., a low-level staff/floor account executing unauthorized administrative or management-level backend actions).\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAPI Integrity and Endpoint Manipulation (OWASP API Top 10):\u003c/strong\u003e Exploiting backend web, mobile, and integration APIs through parameter tampering, mass assignment, or manipulating hidden routing paths to alter server-side data models without using the standard user interface.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eHigh-Impact Stored XSS:\u003c/strong\u003e Stored Cross-Site Scripting payloads that execute within administrative, corporate-facing, or back-office dashboards, or payloads capable of worm-like propagation across accounts (excluding known paths listed below).\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAccount Takeover (ATO) Workflows:\u003c/strong\u003e Critical flaws in authentication, session management, or business logic that result in full account compromise.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eKnown Issues \u0026amp; Conditional Triage Matrix\u003c/h2\u003e\n\n\u003cp\u003eTo prevent systemic blind spots in an era of automated scaling and AI fuzzer deployments, we no longer maintain absolute blanket bans on certain vulnerability classes. Instead, we utilize a \u003cstrong\u003e\"Prove the Business Risk\"\u003c/strong\u003e operational model. \u003c/p\u003e\n\n\u003cp\u003eThe following items are considered \u003cem\u003eKnown Issues\u003c/em\u003e in baseline environments and will be closed as Informational if reported as a theoretical or low-impact finding. However, if a researcher can demonstrate a unique, functional exploit chain that directly bypasses core application security boundaries, they are conditionally eligible for active triage:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eRate Limiting \u0026amp; Brute Force:\u003c/strong\u003e Submissions will only be triaged if missing on critical business-logic pathways resulting in verified fraud or account compromise (e.g., bypassing Multi-Factor Authentication checks, brute-forcing payment checkouts, or execution of high-impact automated account takeover vectors). Generic site-wide page-load rate limiting or standard endpoint brute-forcing remains out of scope.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCSV / Formula Injection:\u003c/strong\u003e Triaged exclusively if a lower-privilege account user can inject malicious payloads into shared enterprise data tables (such as inventory adjustments or menu matrices) that successfully trigger arbitrary command execution upon a manager or admin's local machine during a CSV/Excel export action.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSession Persistence \u0026amp; Invalidation:\u003c/strong\u003e Triaged exclusively if active, authenticated attacker sessions stubbornly persist and fail to terminate across concurrent endpoints following an explicit password modification, account recovery lifecycle event, profile email update, or explicit account logout sequence.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eFile Upload Limitations:\u003c/strong\u003e Bypassing standard format or extension content restrictions will only be considered valid if the researcher provides a functional proof of concept demonstrating successful remote server-side code execution (RCE), persistent cross-user script execution, or system payload retrieval.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut of Scope Vulnerabilities\u003c/h2\u003e\n\n\u003cp\u003eThe following specific vulnerability types, behaviors, and configuration anomalies are explicitly excluded from financial rewards and triage consideration:\u003c/p\u003e\n\n\u003ch3\u003e1. Controlled Web Vulnerabilities \u0026amp; Known Paths\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eReflected \u0026amp; Self-XSS:\u003c/strong\u003e All Reflected XSS, Self-XSS, or XSS requiring local client-side manipulation (e.g., User-Agent header injection).\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eKnown Stored XSS Paths:\u003c/strong\u003e Stored XSS found \u003cem\u003especifically\u003c/em\u003e within the following transactional entities are already known to our security engineering team and are strictly \u003cstrong\u003eOut of Scope\u003c/strong\u003e:\n\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003e/customers\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e/Receipt\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e/Stock\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCross-Site Request Forgery (CSRF):\u003c/strong\u003e CSRF on unauthenticated forms, state-less interactions, or actions with low business impact (e.g., Add/Delete from Cart, Wishlist/Favorites modifications, non-severe user preference toggles, and Log-In/Log-Out CSRF). \u003cem\u003eCSRF is only triaged if it directly facilitates a full, unauthorized Account Takeover (ATO) as determined by Vuln Ops.\u003c/em\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eOpen Redirects:\u003c/strong\u003e Standard URL/Open redirection flaws, unless directly chained to validate token or credential exfiltration.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eText Injection:\u003c/strong\u003e Injection of arbitrary text without HTML, JavaScript, or hyperlink execution capabilities (including Same Site Scripting and generic Content Spoofing).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003e2. Low-Impact Authentication \u0026amp; Enumeration Noise\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eEnumeration:\u003c/strong\u003e Account, user, or email enumeration via basic brute-force testing or standard login/forgot-password error responses. (Valid user account enumeration \u003cem\u003enot\u003c/em\u003e requiring brute-force or side-channel parsing will be considered on a case-by-case basis).\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eClient-Side Auth:\u003c/strong\u003e Browser autocomplete features, saved password vulnerabilities, or local application credential storage behaviors.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCaptchas:\u003c/strong\u003e Weak Captchas or Captcha bypass vulnerabilities.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePassword Exclusions:\u003c/strong\u003e Mail bombing or automated notification flooding via the Password Reset / Forgot Password functionality.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003e3. Environment \u0026amp; Configuration Best Practices\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eDNS/Email Security:\u003c/strong\u003e Missing or misconfigured SPF, DKIM, or DMARC records.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eHTTP Headers \u0026amp; Methods:\u003c/strong\u003e Missing or weak HTTP security headers (e.g., HSTS, X-Frame-Options, X-XSS-Protection, X-Content-Type-Options, CSP configurations) or globally enabled HTTP methods (e.g., OPTIONS enabled) that do not directly expose a functional exploit path.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eClickjacking:\u003c/strong\u003e Clickjacking or UI redressing issues that lack a high-severity secondary impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSSL/TLS Infrastructure:\u003c/strong\u003e Weak cipher suites, lack of Forward Secrecy, or theoretical flaws (e.g., BEAST, BREACH, POODLE, Heartbleed) without a functional custom PoC proving server compromise. Lack of SSL or Mixed Content on non-sensitive assets.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eVerbosity \u0026amp; Information Disclosure:\u003c/strong\u003e Descriptive error pages, stack traces, application errors, HTTP non-200 codes, and standard software banner/fingerprinting disclosures.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePublic Documentation:\u003c/strong\u003e Disclosure of standard public-facing files (e.g., \u003ccode\u003erobots.txt\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eThird-Party Infrastructure:\u003c/strong\u003e Generic directory structure enumeration (unless revealing exceptionally sensitive information), IIS Tilde File disclosures, SSH Username enumeration, or Wordpress Username enumeration.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003e4. Logic \u0026amp; Third-Party Limitations\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eVulnerable Libraries:\u003c/strong\u003e Use of a known-vulnerable library that leads to a low-impact vulnerability (e.g., an outdated jQuery version leading to low-impact XSS) without a functional, unique exploit chain.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eResource Abuse \u0026amp; Over-billing:\u003c/strong\u003e Over-billing, quota-exhaustion, or service disruption attacks against integrated third-party tracking or service APIs (e.g., Google Maps API, Azure Application Insights).\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eNetwork \u0026amp; Cache Abuse:\u003c/strong\u003e HTTP/DNS cache poisoning or External Service Interaction (HTTP) without actionable impact.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAdvanced Infrastructure Scaling Restrictions:\u003c/strong\u003e XXE and SSRF attacks that only provide a localhost/internal host port scan or external port scanning are considered low impact and out of scope. \u003cem\u003ePayouts will be reduced by 50% if proof cannot be provided of further exploitation or system file read capabilities.\u003c/em\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDuplication:\u003c/strong\u003e Multiple recurrences of the exact same vulnerability across different domains or application layouts.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eReport Submission Format\u003c/h2\u003e\n\n\u003cp\u003eWhen reporting vulnerabilities, please use the format below with detailed information and reproducible steps in the Vulnerability Details field:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDescription\u003c/li\u003e\n\u003cli\u003eVulnerable URL/Location\u003c/li\u003e\n\u003cli\u003eSteps to Reproduce\u003c/li\u003e\n\u003cli\u003eLikelihood Analysis\u003c/li\u003e\n\u003cli\u003eImpact Analysis\u003c/li\u003e\n\u003cli\u003eRecommendation\u003c/li\u003e\n\u003cli\u003eOther References (Optional)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003ePre-provisioned testing accounts are available for retrieval at the bottom of this brief.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003eWhen conducting vulnerability research in accordance with this policy, we consider this research to be:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eAuthorized\u003c/strong\u003e under the Computer Fraud and Abuse Act (CFAA) (and local equivalents); we will not pursue legal action for accidental, good-faith policy deviations.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eExempt\u003c/strong\u003e from DMCA circumvention restrictions on security controls.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eLawful\u003c/strong\u003e, constructive, and conducted in good faith.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eFor scope clarifications prior to testing, please contact support@bugcrowd.com.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"0ac16fd9-db44-430d-ac84-ba14299df9a2","name":"Lightspeed Hospitality K-Series","targets":[{"id":"3de44b24-e0ce-4684-ace0-ba8e6a97ba81","uri":"https://manager.trial.lsk.lightspeed.app/","name":"https://manager.trial.lsk.lightspeed.app/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"3d3fc594-a51c-4151-8e05-5d289ee82251","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"3de44b24-e0ce-4684-ace0-ba8e6a97ba81"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"3de44b24-e0ce-4684-ace0-ba8e6a97ba81"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"3de44b24-e0ce-4684-ace0-ba8e6a97ba81"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"3de44b24-e0ce-4684-ace0-ba8e6a97ba81"}],"recentChangeFlags":null},{"id":"fbc08732-55a8-4e86-b787-bebe4a8fa184","uri":"https://mylightspeed.app","name":"mylightspeed.app ","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"3628489f-7788-49aa-90b7-3b3b70989691","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"9c43adae-a48d-4557-b3f0-ab61640ea363","p1MaxCents":750000,"p1MinCents":550000,"p2MaxCents":350000,"p2MinCents":250000,"p3MaxCents":150000,"p3MinCents":75000,"p4MaxCents":50000,"p4MinCents":25000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":5500,"max":7500},"2":{"min":2500,"max":3500},"3":{"min":750,"max":1500},"4":{"min":250,"max":500},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"5b6799d4-3e42-406a-ad4b-4cdcfc6d8b17","name":"Lightspeed Hospitality U-Series","targets":[{"id":"cd345985-aa3b-4059-abfb-c787c59dc06c","uri":"https://hq.breadcrumb.com/hq/restaurants/bounty-cafe-2/","name":"https://hq.breadcrumb.com/hq/restaurants/bounty-cafe-2/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1ce12990-edd5-43c8-a7a4-78ce246a7710","sortOrder":0},"sortOrder":0,"tags":[{"id":"4592d652-bb2d-4ab9-8720-08fe80de0dc4","name":"Backbone","targetId":"cd345985-aa3b-4059-abfb-c787c59dc06c"},{"id":"53917c1d-52c8-41f3-86f5-166e787ece8f","name":"Select2","targetId":"cd345985-aa3b-4059-abfb-c787c59dc06c"},{"id":"9f26f47e-4acd-4d8d-aad2-414b6b367eb0","name":"Handlebars","targetId":"cd345985-aa3b-4059-abfb-c787c59dc06c"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"cd345985-aa3b-4059-abfb-c787c59dc06c"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"cd345985-aa3b-4059-abfb-c787c59dc06c"},{"id":"dd477d24-b394-460d-aaf7-9bd213555968","name":"Ruby","targetId":"cd345985-aa3b-4059-abfb-c787c59dc06c"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"9c43adae-a48d-4557-b3f0-ab61640ea363","p1MaxCents":750000,"p1MinCents":550000,"p2MaxCents":350000,"p2MinCents":250000,"p3MaxCents":150000,"p3MinCents":75000,"p4MaxCents":50000,"p4MinCents":25000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":5500,"max":7500},"2":{"min":2500,"max":3500},"3":{"min":750,"max":1500},"4":{"min":250,"max":500},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"12c513de-e7e2-40e5-b867-91cff0da2390","name":"Out of Scope","targets":[{"id":"8661a58b-1b0b-4fe9-a0aa-09604180033e","uri":"https://lightspeedhq.com/trial ","name":"lightspeedhq.com/trial ","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"0986ad1d-5b26-4117-a743-7d93eb45b509","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"2f4fed3a-7542-49b9-9577-e4c6627886d7","uri":"https://pos-admin.trial.lsk.lightspeed.app","name":"pos-admin.trial.lsk.lightspeed.app","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"470f82f9-421c-425d-a4dc-d832cc54035f","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":2,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[{"id":"a30b9c35-ede9-431c-adcd-bfe78fa9c0ae","attachmentPath":"https://bugcrowd.com/engagements/lightspeed-hospitality/attachments/a30b9c35-ede9-431c-adcd-bfe78fa9c0ae","name":"Out_of_Scope_Issues.pdf","filename":"Out_of_Scope_Issues.pdf","description":null,"icon":"fileOther","size":66291,"sizeLabel":"64.7 KB","uploadedAt":"8 Apr 2026","fileType":"Document","embedUrl":"https://bugcrowd.com/engagements/lightspeed-hospitality/attachments/a30b9c35-ede9-431c-adcd-bfe78fa9c0ae"}],"engagement":{"id":"cb45ce76-8daa-4a4f-ae32-44ca62e4388a","code":"lightspeed-hospitality","state":"in_progress","endsAt":null,"bountyId":"24ef1432-05d9-4102-a068-741fe900afe7","startsAt":"2023-02-21T20:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/2d27/d997/043b1d7f/c5b9a7ab8d615b2d06e99960ab9ab262_lightspeed.jpeg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-12-05T17:49:38.754Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/lightspeed-hospitality","changelogs":"/engagements/lightspeed-hospitality/changelog","submissions":null,"announcements":"/engagements/lightspeed-hospitality/announcements","hallOfFame":"/engagements/lightspeed-hospitality/hall_of_fames","crowdstream":"/engagements/lightspeed-hospitality/crowdstream"},"announcementsCount":9,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/lightspeed-hospitality/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=lightspeed-hospitality\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/lightspeed-hospitality/engagement_subscribers","engagementChangelogsUrl":"/engagements/lightspeed-hospitality/changelog","publishedAt":"2026-06-15T00:30:28.939Z","engagementChangelogUrl":"/engagements/lightspeed-hospitality/changelog/b409de16-0a3b-4cad-9292-92582ced5b2f","createUserFeedbacksUrl":"/engagements/lightspeed-hospitality/feedbacks","engagementCrowdstreamUrl":"/engagements/lightspeed-hospitality/crowdstream","acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}