{"id":"0155df4c-da86-44f0-adec-d3407d5d508e","engagementId":"2d528d45-9239-42ee-8d9e-4387a772bb5b","data":{"brief":{"id":"768d8654-94a2-4a1a-a6a8-a5f85a1c5d0e","name":"LTK Vulnerability Disclosure Engagement","tagline":"LTK is a global technology platform founded in 2011 to empower the world’s premium lifestyle Creators to be a brands' power partner.","description":"\u003cp\u003e\u003cstrong\u003eLTK Vulnerability Disclosure Policy\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eIntroduction\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eAt LTK, we are dedicated to improving our security posture. We appreciate feedback from security researchers and the general public. If you believe you have discovered a vulnerability, privacy issue, exposed data, or any other security issue related to our assets, please contact us by following the policy outlined below.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eSystems in Scope\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eThis policy applies to any digital assets owned, operated, or maintained by LTK. \u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eOur Commitments\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eWhen working with us in compliance with this policy, you can expect us to:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eRespond to your report promptly, and work with you to understand and validate your report.\u003c/li\u003e\n\u003cli\u003eKeep you informed about the progress of a vulnerability as it is processed;\u003c/li\u003e\n\u003cli\u003eWork to remediate discovered vulnerabilities in a timely manner, within our operational constraints; and\u003c/li\u003e\n\u003cli\u003eExtend Safe Harbor for your vulnerability research that is related to this policy.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eOur Expectations\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eIn participating in our vulnerability disclosure program in good faith, we ask that you:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePlay by the rules, including following this policy and any other relevant agreements. If there is any inconsistency between this policy and any other applicable terms, the terms of this policy will prevail.\u003c/li\u003e\n\u003cli\u003eReport any vulnerability you’ve discovered promptly.\u003c/li\u003e\n\u003cli\u003eAvoid violating the privacy of others, disrupting our systems, destroying data, and/or harming user experience;\u003c/li\u003e\n\u003cli\u003eUse only the Official Channels (outlined below) to discuss vulnerability information with us;\u003c/li\u003e\n\u003cli\u003eProvide us a reasonable amount of time (at least 180 days from the initial report) to resolve the issue before you disclose it publicly;\u003c/li\u003e\n\u003cli\u003ePerform testing only on in-scope systems, and respect systems and activities which are out of scope;\u003c/li\u003e\n\u003cli\u003eDo not perform testing that violates any applicable laws or regulations or disrupts or compromises any data that is not your own;\u003c/li\u003e\n\u003cli\u003eIf a vulnerability provides unintended access to data: Limit the amount of data you access to the minimum required for effectively demonstrating a Proof of Concept; and cease testing and submit a report to Inspectiv and LTK (via security@ltk.com) immediately if you encounter any user data during testing, such as Personally Identifiable Information (PII), Personal Healthcare Information (PHI), credit card data, or proprietary information;\u003c/li\u003e\n\u003cli\u003eYou should only interact with test accounts you own or with explicit permission from the account holder.\u003c/li\u003e\n\u003cli\u003eDo not run any automated vulnerability scanning tools against services in scope; no DDoS and no brute force attacks.\u003c/li\u003e\n\u003cli\u003eDo not engage in extortion.\u003c/li\u003e\n\u003cli\u003eNo exfiltration of user or LTK data;\u003c/li\u003e\n\u003cli\u003eNo modification of user or LTK data. \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eRewards\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eLTK does not offer monetary rewards for this program. LTK will not negotiate in response to duress or threats. \u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eOfficial Channels\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003ePlease report security issues here https://bugcrowd.com/engagements/ltk-vdp-pro. Please provide all relevant information. The more details you provide, the easier it will be for us to triage and fix the issue.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eSafe Harbor\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003eWhen conducting vulnerability research, according to this policy, we consider this research conducted under this policy to be:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized concerning any applicable anti-hacking laws, and we will not initiate or support legal action against you for accidental, good-faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eAuthorized concerning any relevant anti-circumvention laws, and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms of Service (TOS) and/or Acceptable Usage Policy (AUP) that would interfere with conducting security research, and we waive those restrictions on a limited basis;\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eYou are expected, as always, to comply with all applicable laws. If legal action is initiated by a third party against you and you have complied with this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.\u003c/p\u003e\n\n\u003cp\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our Official Channels before going any further.\u003c/p\u003e\n\n\u003cp\u003eNote that the Safe Harbor applies only to legal claims under the control of the organization participating in this policy, and that the policy does not bind independent third parties.\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003ch3\u003eScope Overview\u003c/h3\u003e\n\n\u003cp\u003eThis section defines authentication categories, in-scope assets, focused testing missions, testing practices, and out-of-scope items.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch4\u003eAuthentication Scope Categories\u003c/h4\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCategory\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eBlack Box (Shopper/Consumer only)\u003c/td\u003e\n\u003ctd\u003eSelf sign-up is allowed for shopper/consumer facing properties; follow Bugcrowd guidance on account creation.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eAuthenticated (Access-controlled)\u003c/td\u003e\n\u003ctd\u003eTesting may require authenticated access. Do not request or use shared credentials; only test with accounts you own and as explicitly permitted by the program.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eUnauthenticated\u003c/td\u003e\n\u003ctd\u003eTesting limited to endpoints that require no authentication.\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003chr\u003e\n\n\u003ch4\u003eAssets In Scope\u003c/h4\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eEndpoint/Asset\u003c/th\u003e\n\u003cth\u003eDescription\u003c/th\u003e\n\u003cth\u003eAuthentication\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003ehttps://brands.rewardstyle.com/\u003c/td\u003e\n\u003ctd\u003eBrand Platform – Web (Production)\u003c/td\u003e\n\u003ctd\u003eAuthenticated (Access-controlled)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ehttps://creator.shopltk.com/\u003c/td\u003e\n\u003ctd\u003eLTK Creator  – Web (Production)\u003c/td\u003e\n\u003ctd\u003eAuthenticated (Access-controlled)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ehttps://www.shopltk.com/\u003c/td\u003e\n\u003ctd\u003eShopper/Consumer  – Web (Production)\u003c/td\u003e\n\u003ctd\u003eBlack Box (Shopper/Consumer): self sign-up allowed; follow Bugcrowd guidance on account creation.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eAndroid app: https://play.google.com/store/apps/details?id=com.rewardstyle.liketoknowit\u003c/td\u003e\n\u003ctd\u003eLTK Mobile App (Android) Shopper/Consumer And Creator  – (Production)\u003c/td\u003e\n\u003ctd\u003eBlack Box (Shopper/Consumer): self sign-up allowed; follow Bugcrowd guidance on account creation.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eiOS app: https://apps.apple.com/us/app/liketoknow-it/id1154027990\u003c/td\u003e\n\u003ctd\u003eiOS Shopper/Consumer – Mobile (Production)\u003c/td\u003e\n\u003ctd\u003eBlack Box (Shopper/Consumer): self sign-up allowed; follow Bugcrowd guidance on account creation.\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eiOS app: https://apps.apple.com/us/app/ltk-creator-influencer-tools/id632918824\u003c/td\u003e\n\u003ctd\u003eIOS Creator App– Mobile (Production)\u003c/td\u003e\n\u003ctd\u003eAuthenticated (Access-controlled)\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003ch3\u003eVPN and Access Controls\u003c/h3\u003e\n\n\u003cp\u003eIf a Bugcrowd-provided VPN or traffic gateway is required, usage is restricted to in-scope LTK assets and must follow program instructions. Any gateway infrastructure is out of scope for testing; tampering or attempted tampering may result in disqualification from access.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eDocumentation and Resources\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003e\u003ca href=\"https://drive.google.com/file/d/1hRk1bVTu7vPKx8sJmMp5rNW9S2Co0keU/view?usp=sharing\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eCreator/Brand Integration Rules\u003c/a\u003e\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003ca href=\"https://drive.google.com/file/d/1yDmVL51AtuTC7dOSdqgF_S7_98FApV27/view?usp=sharing\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSelf Service Campaign (LTK Connect) Description\u003c/a\u003e\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003ca href=\"https://docs.google.com/document/d/1aIsdAEFWSt1I5ZAVWz7PbYNOFdnABBMQ8DZWnZ894Qg/edit?usp=sharing\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eRelease Notes\u003c/a\u003e\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eOut of Scope\u003c/h3\u003e\n\n\u003cp\u003e\u003cstrong\u003eVulnerabilities discovered or suspected in out-of-scope systems should be reported to the appropriate vendor or applicable authority.\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch4\u003eProgram-Specific\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eAny third-party applications and services that are not owned or operated by LTK\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eLTK physical assets.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003ePosting campaigns to the LTK production marketplace – all assets.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eContacting real Creators via campaigns/messages using Brand accounts in production – all assets.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIDOR via API on https://brands.rewardstyle.com and https://creator.shopltk.com.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eFindings requiring sending a collaboration request and thereafter on https://brands.rewardstyle.com and https://creator.shopltk.com.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch4\u003eMobile-Specific\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eAndroid SSL certificate unpinning.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eAndroid task hijacking.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch4\u003eGeneral\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eAttacks requiring MITM or physical device access.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eAny third-party systems outside the domains listed in scope, or not listed in “Assets In Scope”.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eArbitrary file upload without evidence of execution or impact.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eActivity leading to service disruption (DoS/DDoS), including rate limiting bypass.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eBroken Link Hijacking.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eBlind SSRF without negative impact.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eClickjacking or Tapjacking.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eRecent CVEs (published within 90 days) or CVEs without a PoC.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eCORS misconfiguration on non-sensitive endpoints or without impact.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eCSRF without impact, anonymous-only forms (e.g., contact), or logout CSRF.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eCSV Injection.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDisclosure of known public files/directories (e.g., robots.txt).\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMissing metadata stripping from images/files.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eFunctional/UI/UX bugs and spelling mistakes.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eGoogle Maps API key exposure.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eHTTP request smuggling without impact.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eHost header injection without impact.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIdentification of outdated software.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIP logger vulnerabilities.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eLack of Secure and HTTPOnly cookie flags.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eLack of security speed bump when leaving the site.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eLogin/Forgot Password brute force and lockout not enforced.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMail configuration issues (SPF, DKIM, DMARC).\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMissing HTTP security headers.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eOPTIONS/TRACE enabled.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003ePresence of autocomplete or save password functionality.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003ePre-auth account takeover (“OAuth squatting”).\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eRate limiting or brute force issues.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eSelf-XSS that cannot be used against other users.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eReports sent by automated tools without validation.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eSession fixation.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eSocial engineering (phishing, vishing, smishing).\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eSoftware version disclosure, banner identification, descriptive error messages/headers (e.g., stack traces).\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eSSL attacks (BEAST, BREACH, renegotiation), forward secrecy not enabled, insecure cipher suites.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eSSL certificate expired or misconfigured without impact.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eSubdomain takeover.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eTesting accounts or apps via third-party leaked credentials.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eToken expiration.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eTokens leaked to trusted third parties without impact.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eUsername/Email enumeration.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eViolations of Secure Design Principles.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eSession mismanagement without demonstrated impact (e.g., session persists after logout or profile changes).\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eWeak Captcha/Captcha bypass.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eWordPress XMLRPC issues.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eReporting Channel\u003c/h3\u003e\n\n\u003cp\u003eSubmit findings via the LTK Bugcrowd program page (use Program Q\u0026amp;A for clarifications). Include steps to reproduce, affected endpoint/asset, observed impact, and any relevant screenshots/PoC.\u003c/p\u003e\n\n\u003chr\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"2ceaa1b1-6d8b-4829-9288-ab7c1f63ee44","name":"In‑Scope Targets","targets":[{"id":"b9176bad-07e2-4521-967e-1d9f50b38a5c","uri":"https://brands.rewardstyle.com/","name":"LTK Brand Platform","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ca68fad5-f2f9-4411-9d0e-549da363b189","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"b9176bad-07e2-4521-967e-1d9f50b38a5c"}],"recentChangeFlags":null},{"id":"4af3ce47-8cd9-44ee-a020-ed6ea1dd6525","uri":"https://creator.shopltk.com/","name":"LTK Creator Web App","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b20183ea-7f97-4b43-add4-32de5b357334","sortOrder":1},"sortOrder":1,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"4af3ce47-8cd9-44ee-a020-ed6ea1dd6525"}],"recentChangeFlags":null},{"id":"ac5174d8-a976-45cc-b180-7d249331e5ef","uri":"https://creator.shopltk.com/","name":"LTK Shopper/Consumer Web App","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"0a77ad6e-fb72-42c6-af97-67ace790f1b3","sortOrder":2},"sortOrder":2,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"ac5174d8-a976-45cc-b180-7d249331e5ef"}],"recentChangeFlags":null},{"id":"04c6e67f-d5e0-4a80-b930-2dfcaf7ad57b","uri":"https://play.google.com/store/apps/details?id=com.rewardstyle.liketoknowit","name":"LTK Mobile App (Android)","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"28e4b0de-8e02-4f9c-85db-f63b164f2e5b","sortOrder":3},"sortOrder":3,"tags":[{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"04c6e67f-d5e0-4a80-b930-2dfcaf7ad57b"}],"recentChangeFlags":null},{"id":"7dbdf76c-f6b4-4f0e-9183-0c7b35b23621","uri":"https://apps.apple.com/us/app/liketoknow-it/id1154027990","name":"LTK Shopper/Consumer Mobile App (iOS)","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"7e90a463-1d8e-4c82-924d-1566da8e87f1","sortOrder":4},"sortOrder":4,"tags":[{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"7dbdf76c-f6b4-4f0e-9183-0c7b35b23621"}],"recentChangeFlags":null},{"id":"0f181c3e-5eaa-4e3b-a986-1d1a4a1f9776","uri":"https://apps.apple.com/us/app/ltk-creator-influencer-tools/id632918824","name":"LTK Creator Mobile App (iOS)","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"0b0cffad-3a4e-4a86-bd9a-08dc6c3299cf","sortOrder":5},"sortOrder":5,"tags":[{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"0f181c3e-5eaa-4e3b-a986-1d1a4a1f9776"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003ch3\u003eIn‑Scope Targets\u003c/h3\u003e\n\n\u003cp\u003eThis program covers the following production targets. Test only the assets listed here, within the described access model and notes.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch4\u003eWeb Applications (Production)\u003c/h4\u003e\n\n\u003ctable\u003e\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eTarget\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eEnvironment\u003c/th\u003e\n\u003cth\u003eAccess\u003c/th\u003e\n\u003cth\u003eTech / Stack\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003ehttps://brands.rewardstyle.com/\u003c/td\u003e\n\u003ctd\u003eWebsite\u003c/td\u003e\n\u003ctd\u003eProduction\u003c/td\u003e\n\u003ctd\u003eAuthenticated (access‑controlled)\u003c/td\u003e\n\u003ctd\u003eAuth0 (legacy \u003ccode\u003eauth0.rewardstyle.com\u003c/code\u003e), Tyk Gateway (\u003ccode\u003eprod-tyk-gateway-v1.rewardstyle.com\u003c/code\u003e)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ehttps://creator.shopltk.com/\u003c/td\u003e\n\u003ctd\u003eWebsite\u003c/td\u003e\n\u003ctd\u003eProduction\u003c/td\u003e\n\u003ctd\u003eAuthenticated (access‑controlled)\u003c/td\u003e\n\u003ctd\u003eVue-based Creator Web, Auth0 Creator login (\u003ccode\u003eauth-creator.shopltk.com\u003c/code\u003e)\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ehttps://www.shopltk.com/\u003c/td\u003e\n\u003ctd\u003eWebsite\u003c/td\u003e\n\u003ctd\u003eProduction\u003c/td\u003e\n\u003ctd\u003eBlack Box (shopper/consumer self‑serve)\u003c/td\u003e\n\u003ctd\u003e\u003ccode\u003eltk-vue\u003c/code\u003e (Vue) + Capsule‑Wardrobe component library\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\u003c/table\u003e\n\n\u003chr\u003e\n\n\u003ch4\u003eMobile Applications (Production)\u003c/h4\u003e\n\n\u003ctable\u003e\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eTarget\u003c/th\u003e\n\u003cth\u003eType\u003c/th\u003e\n\u003cth\u003eEnvironment\u003c/th\u003e\n\u003cth\u003eAccess\u003c/th\u003e\n\u003cth\u003eTech / Stack\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003ehttps://play.google.com/store/apps/details?id=com.rewardstyle.liketoknowit\u003c/td\u003e\n\u003ctd\u003eMobile (Android)\u003c/td\u003e\n\u003ctd\u003eProduction\u003c/td\u003e\n\u003ctd\u003eBlack Box (shopper/consumer self‑serve)\u003c/td\u003e\n\u003ctd\u003eLTK Mobile App hosting both Shopper/Consumer and Creator Mobile Apps ; Auth0 shopper/consumer tenants\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ehttps://apps.apple.com/us/app/liketoknow-it/id1154027990\u003c/td\u003e\n\u003ctd\u003eMobile (iOS)\u003c/td\u003e\n\u003ctd\u003eProduction\u003c/td\u003e\n\u003ctd\u003eBlack Box (shopper/consumer self‑serve)\u003c/td\u003e\n\u003ctd\u003eLTK Shopper/Consumer iOS app; Auth0 shopper/consumer tenants\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003ehttps://apps.apple.com/us/app/ltk-creator-influencer-tools/id632918824\u003c/td\u003e\n\u003ctd\u003eMobile (iOS)\u003c/td\u003e\n\u003ctd\u003eProduction\u003c/td\u003e\n\u003ctd\u003eAuthenticated (access‑controlled)\u003c/td\u003e\n\u003ctd\u003eLTK Creator iOS app; Bukimi (WKWebView native‑web interop); Auth0 influencer tenants\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\u003c/table\u003e\n\n\u003chr\u003e\n\n\u003ch4\u003eGeneral Notes\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eShopper/Consumer self‑serve account creation must follow Bugcrowd guidance.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDo not use shared, stolen, or third‑party leaked credentials.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIf you inadvertently access another user’s account or sensitive data, stop testing immediately, submit your report via Bugcrowd, and notify security@ltk.com.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"2d528d45-9239-42ee-8d9e-4387a772bb5b","code":"ltk-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"c2e105e5-62b4-4490-b682-c4fd71afd7ad","startsAt":"2025-10-14T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/2144/4999/97e146ee/cfda697b253c0e508f015c64846e3248_black_LTK_icon_2022Small.jpg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-10-14T18:00:00.042Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/ltk-vdp-pro","changelogs":"/engagements/ltk-vdp-pro/changelog","submissions":null,"announcements":"/engagements/ltk-vdp-pro/announcements","hallOfFame":"/engagements/ltk-vdp-pro/hall_of_fames","crowdstream":"/engagements/ltk-vdp-pro/crowdstream"},"announcementsCount":2,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/ltk-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=ltk-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/ltk-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/ltk-vdp-pro/changelog","publishedAt":"2026-05-06T16:51:54.668Z","engagementChangelogUrl":"/engagements/ltk-vdp-pro/changelog/0155df4c-da86-44f0-adec-d3407d5d508e","createUserFeedbacksUrl":"/engagements/ltk-vdp-pro/feedbacks","engagementCrowdstreamUrl":"/engagements/ltk-vdp-pro/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}