{"id":"0c06fd61-053e-4724-a145-506fde7e211c","engagementId":"203e0cef-5bd6-403c-a86a-8d2acfc2e3ab","data":{"brief":{"id":"83dfe659-bcc9-4b9e-9c3a-5504afc1e08c","name":"Lightspeed Retail","tagline":"Welcome to the Lightspeed Retail Bug Bounty. We are committed to fostering a collaborative relationship with the global research community by actively recognizing and rewarding those who help fortify our retail platform.","description":"\u003ch2\u003eIntroduction\u003c/h2\u003e\n\n\u003cp\u003eWelcome to Lightspeed Retail. Help us fortify and secure our core global commerce infrastructure, spanning our omni-channel Ecommerce orchestration layers (\u003cstrong\u003eE-Series\u003c/strong\u003e) and our cloud-based point-of-sale systems (\u003cstrong\u003eX-Series\u003c/strong\u003e). The Lightspeed Bug Bounty Program is a cornerstone of our commitment to platform resilience, and we actively value collaboration with the global security research community to harden our ecosystem.\u003c/p\u003e\n\n\u003cp\u003eThis page is designed exclusively for security researchers. For general information regarding our corporate security practices, please visit our \u003ca href=\"https://www.lightspeedhq.com/security/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eMain Security Portal\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003ePublic Disclosure Policy\u003c/h2\u003e\n\n\u003cp\u003eThis program operates under a strict Coordinated Disclosure model. Because this is an invite-only environment, you must not discuss, publish, or leak any vulnerabilities or program details (including fully remediated or closed findings) outside of this platform under any circumstances. \u003c/p\u003e\n\n\u003cp\u003eFailure to comply with these boundaries constitutes a severe policy violation and will result in immediate removal from the program, Bugcrowd platform escalation, and potential legal consequences. This program adheres fundamentally to \u003ca href=\"https://www.bugcrowd.com/resources/hacker-resources/standard-disclosure-terms/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd’s Standard Disclosure Terms\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003eRatings and Rewards Policy\u003c/h2\u003e\n\n\u003cp\u003eFor the initial prioritization and rating of findings, this program utilizes the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy (VRT)\u003c/a\u003e. \u003c/p\u003e\n\n\u003cblockquote\u003e\n\u003cp\u003e💡 \u003cstrong\u003eTriage Transparency:\u003c/strong\u003e In certain cases, a vulnerability's priority level may be modified due to its real-world likelihood or unique architectural business impact. In any instance where an issue is downgraded, a full, detailed technical explanation will be provided to the researcher—along with an open opportunity to appeal the ticket and present a technical case for a higher priority level.\u003c/p\u003e\n\u003c/blockquote\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eTesting Rules of Engagement\u003c/h2\u003e\n\n\u003cp\u003eTo protect the integrity of our staging infrastructure and avoid accidental IP blocks by our automated defense systems, \u003cstrong\u003eall testing traffic must be clearly identifiable\u003c/strong\u003e.\u003c/p\u003e\n\n\u003ch3\u003e1. Unauthenticated Testing Guardrails\u003c/h3\u003e\n\n\u003cp\u003eUnauthenticated testing must focus on publicly exposed storefront endpoints, login gateways, and public checkout APIs to identify logical flaws, injection vectors, or authentication bypasses. \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eTraffic Attribution (Mandatory):\u003c/strong\u003e Because these tests are performed without an active user session, researchers \u003cstrong\u003emust\u003c/strong\u003e append a custom header to all HTTP traffic containing their unique Bugcrowd identifier (e.g., \u003ccode\u003eX-Bugcrowd-Ninja: [Your_Username]\u003c/code\u003e). \u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eInfrastructure Exclusions:\u003c/strong\u003e Generic infrastructure probing, port scanning, banner grabbing, and volume-based network directory brute-forcing are strictly out of scope and will trigger automated blocking.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003e2. Authenticated Testing Guidance\u003c/h3\u003e\n\n\u003cp\u003eAuthenticated testing must focus on deep business logic flaws, multi-tenant boundaries, data isolation, and authorization states within the retail management layers. \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eCredentials \u0026amp; Environments:\u003c/strong\u003e These tests must be performed exclusively using the environments you have personally created or via pre-provisioned sandboxes provided to you at the bottom of this brief. Accessing, interacting with, or modifying data on any live, operational production customer retail stores is strictly prohibited.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e","industryTagId":"9ed1ce49-a148-438f-92d3-0b8d70b6a8ae","targetsOverview":"\u003ch2\u003eIntroduction\u003c/h2\u003e\n\n\u003cp\u003eWelcome to Lightspeed Retail. Help us fortify and secure our core global commerce infrastructure, spanning our omni-channel Ecommerce orchestration layers (\u003cstrong\u003eE-Series\u003c/strong\u003e) and our cloud-based point-of-sale systems (\u003cstrong\u003eX-Series\u003c/strong\u003e). The Lightspeed Bug Bounty Program is a cornerstone of our commitment to platform resilience, and we actively value collaboration with the global security research community to harden our ecosystem.\u003c/p\u003e\n\n\u003cp\u003eThis page is designed exclusively for security researchers. For general information regarding our corporate security practices, please visit our \u003ca href=\"https://www.lightspeedhq.com/security/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eMain Security Portal\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003ePublic Disclosure Policy\u003c/h2\u003e\n\n\u003cp\u003eThis program operates under a strict Coordinated Disclosure model. Because this is an invite-only environment, you must not discuss, publish, or leak any vulnerabilities or program details (including fully remediated or closed findings) outside of this platform under any circumstances. \u003c/p\u003e\n\n\u003cp\u003eFailure to comply with these boundaries constitutes a severe policy violation and will result in immediate removal from the program, Bugcrowd platform escalation, and potential legal consequences. This program adheres fundamentally to \u003ca href=\"https://www.bugcrowd.com/resources/hacker-resources/standard-disclosure-terms/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd’s Standard Disclosure Terms\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003eRatings and Rewards Policy\u003c/h2\u003e\n\n\u003cp\u003eFor the initial prioritization and rating of findings, this program utilizes the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy (VRT)\u003c/a\u003e. \u003c/p\u003e\n\n\u003cblockquote\u003e\n\u003cp\u003e💡 \u003cstrong\u003eTriage Transparency:\u003c/strong\u003e In certain cases, a vulnerability's priority level may be modified due to its real-world likelihood or unique architectural business impact. In any instance where an issue is downgraded, a full, detailed technical explanation will be provided to the researcher—along with an open opportunity to appeal the ticket and present a technical case for a higher priority level.\u003c/p\u003e\n\u003c/blockquote\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eTesting Rules of Engagement\u003c/h2\u003e\n\n\u003cp\u003eTo protect the integrity of our staging infrastructure and avoid accidental IP blocks by our automated defense systems, \u003cstrong\u003eall testing traffic must be clearly identifiable\u003c/strong\u003e.\u003c/p\u003e\n\n\u003ch3\u003e1. Unauthenticated Testing Guardrails\u003c/h3\u003e\n\n\u003cp\u003eUnauthenticated testing must focus on publicly exposed storefront endpoints, login gateways, and public checkout APIs to identify logical flaws, injection vectors, or authentication bypasses. \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eTraffic Attribution (Mandatory):\u003c/strong\u003e Because these tests are performed without an active user session, researchers \u003cstrong\u003emust\u003c/strong\u003e append a custom header to all HTTP traffic containing their unique Bugcrowd identifier (e.g., \u003ccode\u003eX-Bugcrowd-Ninja: [Your_Username]\u003c/code\u003e). \u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eInfrastructure Exclusions:\u003c/strong\u003e Generic infrastructure probing, port scanning, banner grabbing, and volume-based network directory brute-forcing are strictly out of scope and will trigger automated blocking.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003e2. Authenticated Testing Guidance\u003c/h3\u003e\n\n\u003cp\u003eAuthenticated testing must focus on deep business logic flaws, multi-tenant boundaries, data isolation, and authorization states within the retail management layers. \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eCredentials \u0026amp; Environments:\u003c/strong\u003e These tests must be performed exclusively using the environments you have personally created or via pre-provisioned sandboxes provided to you at the bottom of this brief. Accessing, interacting with, or modifying data on any live, operational production customer retail stores is strictly prohibited.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eProgram Rules\u003c/h2\u003e\n\n\u003ch3\u003eEligibility\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eInternal Personnel:\u003c/strong\u003e Current employees, contractors, or individuals with a direct professional relationship with our organization are ineligible to participate.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eFormer Employees:\u003c/strong\u003e Submissions from former Lightspeed employees are strictly ineligible for validation or rewards within one year (365 days) of their official departure date.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eLegal Compliance:\u003c/strong\u003e Researchers must comply with all applicable local, national, and international laws. Non-compliance results in immediate program disqualification.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eProfile Requirements:\u003c/strong\u003e Only public, viewable, and verifiable Bugcrowd profiles are eligible for participation and rewards.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003ePlatform Channel:\u003c/strong\u003e All communication and compensation must go directly through Bugcrowd; internal employees cannot bypass this process.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eScope \u0026amp; Target Guidance\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eStrict Target Boundaries:\u003c/strong\u003e Only security vulnerabilities found within explicitly listed domains and applications are in scope. Testing assets or subdomains outside the defined target list without written authorization is strictly prohibited.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eData Privacy:\u003c/strong\u003e Personal Identifiable Information (PII) or system metadata extraction must be limited to the absolute minimum required to prove impact. If sensitive data is accidentally exposed, stop testing immediately, do not download/cache the information, and submit your report right away.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCredential Leaks \u0026amp; OSINT:\u003c/strong\u003e We welcome valid open-source intelligence (OSINT) regarding exposed Lightspeed employee credentials containing the \u003ccode\u003e@lightspeedhq.com\u003c/code\u003e domain. Valid submissions will be evaluated case-by-case based on real business risk.\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cem\u003eExclusion:\u003c/em\u003e Credentials surfaced via criminal activity (e.g., dark web forum dumps, malware stealer logs) are strictly out of scope and ineligible for rewards.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eProof of Concept (PoC) Limits:\u003c/strong\u003e Limit data collection and exploitation steps to the absolute minimum required to effectively demonstrate a working proof of concept.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eStrictly Enforced Testing Restrictions\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eEnvironment Separation:\u003c/strong\u003e Testing must only be conducted against store environments you have personally created for research purposes. Accessing, interacting with, or modifying data on any live, operational customer retail stores will result in immediate program disqualification.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAccount Abuse Boundaries:\u003c/strong\u003e Do not abuse endpoints with excessive or aggressive injection requests. Do not attempt unauthorized password modifications or password-recovery brute-forcing on accounts you do not control.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eProhibited Actions\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eAny testing that impacts the reliability, availability, or operational uptime of our systems.\u003c/li\u003e\n\u003cli\u003ePhysical security testing of corporate facilities, employees, warehouses, or equipment.\u003c/li\u003e\n\u003cli\u003eSocial engineering techniques, including phishing, vishing, or spamming.\u003c/li\u003e\n\u003cli\u003eDenial of Service (DoS) or Distributed Denial of Service (DDoS) attacks.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAutomated Volume Scanning:\u003c/strong\u003e Extensive or aggressive scans using automated tools are strictly prohibited. Testing must be manual and targeted. High-volume scanning will trigger automatic IP blocks.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCorporate Integration Isolation:\u003c/strong\u003e Do not test third-party services and integrations utilized by clients (e.g., \u003ccode\u003ex-series-support.lightspeedhq.com\u003c/code\u003e) without a valid PoC proving direct, cascading impact on core Lightspeed users.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eCorporate Buffer Policies\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eAcquisition Safe Harbor Buffer:\u003c/strong\u003e Security bugs identified in software or platforms belonging to newly acquired companies are explicitly ineligible for triage and rewards for a period of \u003cstrong\u003e90 days\u003c/strong\u003e following the public acquisition announcement.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eN-Day Vulnerability Buffer:\u003c/strong\u003e Publicly released zero-day vulnerabilities in underlying internet infrastructure or software libraries are ineligible for rewards for a period of \u003cstrong\u003e3 days (72 hours)\u003c/strong\u003e following their initial public disclosure.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003ePlatform Specific Testing Guidance\u003c/h2\u003e\n\n\u003ch3\u003e1. Lightspeed eCom (E-Series)\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eAccount Setup:\u003c/strong\u003e Register your test environment via \u003ccode\u003ehttps://my.ecwid.com/cp/#register\u003c/code\u003e. You \u003cstrong\u003emust\u003c/strong\u003e utilize your official Bugcrowd email platform alias (\u003ccode\u003e[Username]@bugcrowdninja.com\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSubdomain Naming Convention:\u003c/strong\u003e When configuring your Instant Site domain (\u003ccode\u003e[yourstore].company.site\u003c/code\u003e), you must append the string \u003ccode\u003ebugbounty\u003c/code\u003e to the subdomain layout (e.g., \u003ccode\u003e[yourstorebugbounty].company.site\u003c/code\u003e) to facilitate automated backend identification.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eExtended Testing Needs:\u003c/strong\u003e If your research requires advanced feature sets or plan-level changes to validate a flaw, submit a request via your report detailing your store account layout, and our team can adjust the subscription tier without charge.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAPI Sandbox:\u003c/strong\u003e To pull custom Postman collections and test raw API query behaviors, leverage the official development playground: \u003ccode\u003ehttps://api-playground.ecwid.com/#!/\u003c/code\u003e. Review the \u003ca href=\"https://api-docs.ecwid.com/reference/overview\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eE-Series API Documentation\u003c/a\u003e for structural formatting.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003e2. Lightspeed Retail (X-Series)\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eAccount Setup:\u003c/strong\u003e Create your trial environments exclusively using your Bugcrowd email platform alias (\u003ccode\u003e[Username]@bugcrowdninja.com\u003c/code\u003e). Avoid creating excessive or rapid trial accounts against the public signup workflow.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eAuthorized Authorization Testing Enclaves:\u003c/strong\u003e Access control and privilege escalation testing within an X-Series environment must be focused around the following defined system profiles and permission zones:\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth style=\"text-align: left\"\u003eAccount Types\u003c/th\u003e\n\u003cth style=\"text-align: left\"\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd style=\"text-align: left\"\u003e\u003cstrong\u003eAdmin\u003c/strong\u003e\u003c/td\u003e\n\u003ctd style=\"text-align: left\"\u003eThe primary account owner with full platform access (Must be tied to your Bugcrowd alias).\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd style=\"text-align: left\"\u003e\u003cstrong\u003eNon-Admin\u003c/strong\u003e\u003c/td\u003e\n\u003ctd style=\"text-align: left\"\u003eLimited profile accounts (Managers, Cashiers) with custom restricted permission maps.\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth style=\"text-align: left\"\u003eAccount-Based Permission Map\u003c/th\u003e\n\u003cth style=\"text-align: left\"\u003eTarget Sub-Areas For Privilege Testing\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd style=\"text-align: left\"\u003e\u003cstrong\u003eMain Area: Sell\u003c/strong\u003e\u003c/td\u003e\n\u003ctd style=\"text-align: left\"\u003eSales History\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd style=\"text-align: left\"\u003e\u003cstrong\u003eMain Area: Catalog\u003c/strong\u003e\u003c/td\u003e\n\u003ctd style=\"text-align: left\"\u003ePromotions, Gift Cards\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd style=\"text-align: left\"\u003e\u003cstrong\u003eMain Area: Setup\u003c/strong\u003e\u003c/td\u003e\n\u003ctd style=\"text-align: left\"\u003eUsers, Apps, Personal Tokens, Store Credits\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003ch4\u003e⚠️ Authorization \u0026amp; IDOR Severity Matrix\u003c/h4\u003e\n\n\u003cp\u003eTo ensure consistency, X-Series privilege escalation findings are strictly triaged against the following business-impact thresholds:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eCross-Tenant IDOR (Store A to Store B):\u003c/strong\u003e Standard triage rules apply (Eligible for full Critical/High reward structures).\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eIntra-Store Unauthorized Write Access:\u003c/strong\u003e If a Non-Admin user account can successfully execute unauthorized Write operations (Create/Update/Delete) within their \u003cem\u003eown\u003c/em\u003e store structure, it is capped at a flat \u003cstrong\u003eP4 / Low\u003c/strong\u003e minimum bounty payout.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eIntra-Store Unauthorized Read Access:\u003c/strong\u003e If a Non-Admin user account can merely read or view unauthorized data models within their \u003cem\u003eown\u003c/em\u003e store structure, it is completely \u003cstrong\u003eOut of Scope\u003c/strong\u003e and ineligible for rewards.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAreas of Particular Interest\u003c/h2\u003e\n\n\u003cp\u003eWe prioritize findings that expose severe backend flaws, data exposure risks, or cross-tenant contamination.\u003c/p\u003e\n\n\u003ch3\u003eGlobal Focus Areas\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eServer-Side Request Forgery (SSRF)\u003c/li\u003e\n\u003cli\u003eSQL Injection (SQLi) and functional Command Injection\u003c/li\u003e\n\u003cli\u003eCross-Tenant Insecure Direct Object References (IDOR) impacting separate retail organizations\u003c/li\u003e\n\u003cli\u003eOpen Redirect flaws that demonstrate a definitive, secondary high-severity impact (e.g., OAuth token theft to an external domain)\u003c/li\u003e\n\u003cli\u003eUnauthorized PII or sensitive system data disclosure\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eE-Series (Ecwid) Targeted Priorities\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eRemote Code Execution (RCE) or arbitrary server-side code execution\u003c/li\u003e\n\u003cli\u003eAuthentication bypass workflows targeting access to \u003ccode\u003emy.ecwid.com/cp\u003c/code\u003e\n\u003c/li\u003e\n\u003cli\u003eComplete circumvention of app extension or admin permission models\u003c/li\u003e\n\u003cli\u003eHigh-impact Cross-Site Request Forgery (CSRF) targeting critical administrative state modifications\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eKnown Issues \u0026amp; Conditional Triage Matrix\u003c/h2\u003e\n\n\u003cp\u003eTo prevent systemic blind spots in an era of automated scaling and AI fuzzer deployments, we no longer maintain absolute blanket bans on certain vulnerability classes. Instead, we utilize a \u003cstrong\u003e\"Prove the Business Risk\"\u003c/strong\u003e operational model. \u003c/p\u003e\n\n\u003cp\u003eThe following items are considered \u003cem\u003eKnown Issues\u003c/em\u003e in baseline environments and will be closed as Informational if reported as a theoretical or low-impact finding. However, if a researcher can demonstrate a unique, functional exploit chain that directly bypasses core application security boundaries, they are conditionally eligible for active triage:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eRate Limiting \u0026amp; Brute Force:\u003c/strong\u003e Submissions will only be triaged if missing on critical business-logic pathways resulting in verified fraud or account compromise (e.g., automated brute-forcing or generation of retail Gift Cards and promotional voucher codes, bypassing Multi-Factor Authentication checks on administrative profile updates, or brute-forcing Personal Tokens). Generic site-wide page-load rate limiting remains out of scope.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCSV / Formula Injection:\u003c/strong\u003e Triaged exclusively if a user can inject malicious payloads into shared retail data tables (such as Sales History lines, Promotions descriptions, or inventory matrices) that successfully trigger arbitrary command execution upon a merchant administrator's local machine during a CSV/Excel export action.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSession Persistence \u0026amp; Invalidation:\u003c/strong\u003e Triaged exclusively if active, authenticated sessions or application API tokens stubbornly persist and fail to terminate across concurrent endpoints following an explicit profile password modification, account recovery lifecycle event, profile email change, or session-revocation action.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eCDN File Hosting Abuse (E-Series):\u003c/strong\u003e Triaged exclusively if a researcher can bypass standard input filters to drop and persistently serve active malicious script files, custom HTML, or cross-site tracking packages directly via our asset delivery networks to execute verified phishing campaigns under an official Lightspeed trusted domain.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut of Scope Vulnerabilities\u003c/h2\u003e\n\n\u003cp\u003eThe following specific vulnerability types, behaviors, and configuration anomalies are explicitly excluded from financial rewards and triage consideration:\u003c/p\u003e\n\n\u003ch3\u003e1. Designed Product Features \u0026amp; Client Controls\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eDesigned Merchant Customization (E-Series):\u003c/strong\u003e E-Series platforms natively allow store owners to embed custom HTML and JavaScript into their storefronts and checkouts. Consequently, any issue where a store administrator inserts scripts into their \u003cem\u003eown\u003c/em\u003e storefront, or scenarios where storefront areas execute within an admin-panel \u003ccode\u003e\u0026lt;iframe\u0026gt;\u003c/code\u003e, are considered \u003cstrong\u003edesigned platform behavior\u003c/strong\u003e and are out of scope.\u003c/li\u003e\n\u003cli\u003eStored XSS executing inside any analytical report templates under the \"Reporting\" subsystem.\u003c/li\u003e\n\u003cli\u003eCross-Site Scripting (XSS) anomalies specific to Angular frameworks, or XSS execution constrained within a sandbox \u003ccode\u003e\u0026lt;iframe\u0026gt;\u003c/code\u003e element.\u003c/li\u003e\n\u003cli\u003eLocal mobile findings reliant on a rooted/jailbroken device, physical access to the target hardware, or data extraction from unsecured physical local backups.\u003c/li\u003e\n\u003cli\u003eSubmissions targeting the Token Request API endpoint or Mobile SSL Pinning mechanics within the Lightspeed Retail POS (X) iOS app.\u003c/li\u003e\n\u003cli\u003eExposed keys that are explicitly intended to be publicly available (e.g., public client-side deployment keys).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003e2. General Web \u0026amp; Formatting Noise\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eSelf-XSS (Reports require proof of cross-user compromise without self-sabotage).\u003c/li\u003e\n\u003cli\u003eXSS requiring full control over localized HTTP transport headers (e.g., Referer, Host, User-Agent fields).\u003c/li\u003e\n\u003cli\u003eInconsistent character validation or length mismatches between UI input fields and backend APIs lacking verified security impact.\u003c/li\u003e\n\u003cli\u003eLow-impact Cross-Site Request Forgery (e.g., Login/Logout/Signup CSRF, or CSRF targeting modification of unauthenticated shopping carts).\u003c/li\u003e\n\u003cli\u003eOpen Redirects lacking a functional, secondary credential/token exfiltration vector.\u003c/li\u003e\n\u003cli\u003eText Injection, HTML Injection, IFrame Injection, Hyperlink Injection, Content Spoofing, or Tabnabbing.\u003c/li\u003e\n\u003cli\u003eInternationalized Domain Name (IDN) homograph attacks or Broken Link Hijacking.\u003c/li\u003e\n\u003cli\u003ePassword not required on non-sensitive actions, or general gaps in password complexity metrics.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003e3. Environment \u0026amp; Infrastructure Policy Exclusions\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eRaw scanner outputs or unconfirmed automated vulnerability reports.\u003c/li\u003e\n\u003cli\u003eMissing HTTP security headers, missing cookie flags on non-sensitive session models, or globally enabled HTTP methods (e.g., OPTIONS).\u003c/li\u003e\n\u003cli\u003eInfrastructure verbose pages, stack traces, descriptive error logs, or software version banner disclosures.\u003c/li\u003e\n\u003cli\u003eDomain mail configuration best practices (missing or incomplete SPF, DKIM, DMARC records) and general mail system abuse.\u003c/li\u003e\n\u003cli\u003eStandard public documentation mapping files (e.g., \u003ccode\u003erobots.txt\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eDistributed Denial of Service (DDoS), network DoS, or self-DoS vulnerabilities.\u003c/li\u003e\n\u003cli\u003eVulnerabilities affecting users on outdated, deprecated, or unsupported browsers (more than 2 stable versions behind the current release).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eReport Submission Format\u003c/h2\u003e\n\n\u003cp\u003eWhen reporting vulnerabilities, please use the format below with detailed information and reproducible steps in the Vulnerability Details field:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDescription\u003c/li\u003e\n\u003cli\u003eVulnerable URL/Location\u003c/li\u003e\n\u003cli\u003eSteps to Reproduce\u003c/li\u003e\n\u003cli\u003eLikelihood Analysis\u003c/li\u003e\n\u003cli\u003eImpact Analysis\u003c/li\u003e\n\u003cli\u003eRecommendation\u003c/li\u003e\n\u003cli\u003eOther References (Optional)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003eWhen conducting vulnerability research in accordance with this policy, we consider this research to be:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eAuthorized\u003c/strong\u003e under the Computer Fraud and Abuse Act (CFAA) (and local equivalents); we will not pursue legal action for accidental, good-faith policy deviations.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eExempt\u003c/strong\u003e from DMCA circumvention restrictions on security controls.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eLawful\u003c/strong\u003e, constructive, and conducted in good faith.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eFor scope clarifications prior to testing, please contact support@bugcrowd.com.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":false,"additionalInformation":""},"scope":[{"id":"44352953-b00c-4313-ac26-c3eb645d7f93","name":"Lightspeed Retail X-Series In Scope Targets","targets":[{"id":"15110968-9fc1-4568-bf15-d81afbd9d571","uri":"https://developers.retail.lightspeed.app","name":" developers.retail.lightspeed.app","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"88cbb0df-52cf-4a67-88f2-3f585ae7922e","sortOrder":0},"sortOrder":0,"tags":[{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"15110968-9fc1-4568-bf15-d81afbd9d571"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"15110968-9fc1-4568-bf15-d81afbd9d571"}],"recentChangeFlags":null},{"id":"983a060e-0cbd-417e-9caa-6018243b2926","uri":"https://payment-connectors.vendhq.com/","name":"payment-connectors.vendhq.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"288ba3e4-c35d-4971-8a1f-dd9799878656","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"983a060e-0cbd-417e-9caa-6018243b2926"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"983a060e-0cbd-417e-9caa-6018243b2926"}],"recentChangeFlags":null},{"id":"8acae2d5-4fac-42c7-87ab-21d4c2535b70","uri":"https://store.retail.lightspeed.app","name":"store.retail.lightspeed.app","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"cd3ea0df-300d-4be4-a9bb-f98cd900c999","sortOrder":0},"sortOrder":0,"tags":[{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"8acae2d5-4fac-42c7-87ab-21d4c2535b70"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"8acae2d5-4fac-42c7-87ab-21d4c2535b70"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"8acae2d5-4fac-42c7-87ab-21d4c2535b70"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"9c43adae-a48d-4557-b3f0-ab61640ea363","p1MaxCents":750000,"p1MinCents":550000,"p2MaxCents":350000,"p2MinCents":250000,"p3MaxCents":150000,"p3MinCents":75000,"p4MaxCents":50000,"p4MinCents":25000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":5500,"max":7500},"2":{"min":2500,"max":3500},"3":{"min":750,"max":1500},"4":{"min":250,"max":500},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"40d80a0e-a58e-4e31-a09e-28c78eba1e5a","name":"Lightspeed Ecommerce E-Series In Scope Targets","targets":[{"id":"180dfed8-fbbd-40db-a6e8-dbd3a5adc0f1","uri":"","name":"https://apps.apple.com/us/app/ecwid-ecommerce/id626731456","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"18cc6589-0712-4fcc-9e73-419db2d681f8","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"05ffc0c9-63e0-4ffb-aa00-f07e023bea6c","uri":"","name":"https://play.google.com/store/apps/details?id=com.ecwid.android\u0026pli=1","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b56556ca-df2a-49bc-8551-8a92b5ab3a88","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null},{"id":"6b93737b-80a3-4c2d-8155-e5c7ffb79fb1","uri":"https://app.ecwid.com/api/v3/","name":"https://app.ecwid.com/api/v3/\t","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"96c9cfaa-77c8-48b3-b5b9-61ddbdd23d2b","sortOrder":2},"sortOrder":2,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"9c43adae-a48d-4557-b3f0-ab61640ea363","p1MaxCents":750000,"p1MinCents":550000,"p2MaxCents":350000,"p2MinCents":250000,"p3MaxCents":150000,"p3MinCents":75000,"p4MaxCents":50000,"p4MinCents":25000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cul\u003e\n\u003cli\u003eThis is the \u003cstrong\u003eControl Panel\u003c/strong\u003e - https://my.ecwid.com\u003cbr\u003e\u003c/li\u003e\n\u003cli\u003eThis is the \u003cstrong\u003eStorefront Panel\u003c/strong\u003e - [yourstore].company.site\u003cbr\u003e\u003c/li\u003e\n\u003cli\u003eAPI - https://app.ecwid.com/api/v3/\u003cbr\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003ePlease note that \u003cstrong\u003e\u0026quot;yourstore\u0026quot;\u003c/strong\u003e is a \u003cstrong\u003eplaceholder only\u003c/strong\u003e in the target scope. When you register an account, you will have your own Instant site domain in your store that you can edit in the form of  [yourstore].company.site. \u003c/p\u003e","rewardRangeData":{"1":{"min":5500,"max":7500},"2":{"min":2500,"max":3500},"3":{"min":750,"max":1500},"4":{"min":250,"max":500},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"308ea9af-59ec-48ca-9dbb-a1f8e1c128d3","name":"Out of Scope Targets","targets":[{"id":"163fd1a6-a7f4-4e9b-a6a0-7747e116963f","uri":"","name":"x-series-support.lightspeedhq.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"51a556d9-202b-4144-8609-55e3e178024a","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"9eecc5fc-894c-457c-87aa-7fa79896e080","uri":"","name":"vendhq.force.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"7575f46b-ae43-43be-9c18-2db0c7f8b968","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"d6500b9d-a1d4-49c8-9084-1e4b05fabd48","uri":"","name":"vendimageuploadcdn.global.ssl.fastly.net","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"189c70c1-91ba-4d60-a2e4-ccb9f82df228","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"bfc782f8-6999-449d-be45-baf8ce70fd2f","uri":"","name":"partners.vendhq.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"aee41f25-c4b8-4b86-9689-9323225d2623","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"f30b4be1-d885-4650-9eb5-fd6df0e86fc1","uri":"","name":"track.api.vendhq.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"7db7b876-d64a-4a1d-83df-0b5e4efb12c6","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"b61782b2-3f1a-4c0f-a4f2-3167474595ff","uri":"","name":"your-store.vendecommerce.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"df5a1c3d-bcee-4d59-b9fa-fbaaf610d963","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"8f65bd57-fa36-4c75-9743-a5a25e2ac9d9","uri":"","name":"partnerportal.vendhq.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"d00f59d7-7f45-43aa-93f3-2953b256b65d","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"b6fff1f0-a6a8-45e1-9f36-5384987b9e5f","uri":"","name":"https://support.ecwid.com/hc/en-us","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"3d0f48f5-d3f2-4885-bc29-a6922db88a2f","sortOrder":7},"sortOrder":7,"tags":null,"recentChangeFlags":null},{"id":"d4d118aa-7bf5-468f-a1ef-c534a98ab140","uri":"","name":"https://www.ecwid.com/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1bad8b76-d1b6-4383-a4a3-18343f09848b","sortOrder":8},"sortOrder":8,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":2,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003ePlease be sure to check the out of scope list below on the brief for further items you should not report. The section begins with the following:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePrivilege escalation and Insecure Direct Object References (IDOR) issues that have read/view access to endpoints in the scope of the same retailer store\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"203e0cef-5bd6-403c-a86a-8d2acfc2e3ab","code":"lightspeed-retail","state":"in_progress","endsAt":null,"bountyId":"7b1e4498-42aa-47d4-bbc7-be0878985e2f","startsAt":"2022-09-27T19:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Retail","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/364d/8cfc/b539163b/4118517e824c9522776dceb0440c7d14_Lightspeed_Flame.png","logoBackgroundColor":"#000000","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":false,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-12-05T17:41:55.188Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/lightspeed-retail","changelogs":"/engagements/lightspeed-retail/changelog","submissions":null,"announcements":"/engagements/lightspeed-retail/announcements","hallOfFame":"/engagements/lightspeed-retail/hall_of_fames","crowdstream":"/engagements/lightspeed-retail/crowdstream"},"announcementsCount":6,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/lightspeed-retail/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=lightspeed-retail\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/lightspeed-retail/engagement_subscribers","engagementChangelogsUrl":"/engagements/lightspeed-retail/changelog","publishedAt":"2026-06-15T00:35:55.299Z","engagementChangelogUrl":"/engagements/lightspeed-retail/changelog/0c06fd61-053e-4724-a145-506fde7e211c","createUserFeedbacksUrl":"/engagements/lightspeed-retail/feedbacks","engagementCrowdstreamUrl":"/engagements/lightspeed-retail/crowdstream","acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}