{"id":"a9b2ddee-3d7d-48d0-8a15-7fcb948105d4","engagementId":"b8c43eb1-1dd9-498a-94ee-484ffd138a0e","data":{"brief":{"id":"23b88698-6203-4d06-9b4e-0a402f6a76de","name":"OLX Group VDP","tagline":"OLX Group is a global online marketplace, founded in 2006 and operating in 45 countries.","description":"\u003cp\u003eOLX values the input of the security community to create a more secure Internet and welcomes the opportunity to collaborate with community members who share this common goal.\u003c/p\u003e\n\n\u003cp\u003eWe take security issues seriously. If you believe you've detected a vulnerability within our products we'd like to hear about it. We'll investigate all reports and do our best to fix these issues as soon as possible.\u003c/p\u003e\n\n\u003cp\u003eThis coordinated vulnerability disclosure program (VDP) is limited to security vulnerabilities identified within OLX's public online presence. \u003c/p\u003e\n\n\u003ch2\u003eRatings:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"1bf3970a-395b-4456-b261-d04dab482af2","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as In-Scope. \u003cem\u003eAny domain/property of OLX Group not listed in the targets section is out of scope. This includes any/all subdomains not listed above.\u003c/em\u003e \u003c/p\u003e\n\n\u003cp\u003eIf you believe you've identified a vulnerability on a system outside the scope, please reach out to support@bugcrowd.com before submitting.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eTarget Information\u003c/h2\u003e\n\n\u003cp\u003ePlease do not use automated vulnerability scanners on this program. Custom scripts and fuzzing tools are permitted, but if using them, please keep your traffic to six requests per second or less. Additionally, it’s worth noting that the client already runs automated scans from Acunetix, Zap, Nessus, et al., against the in-scope targets – so using these tools is likely of minimal utility to researchers. As such, please avoid using them unless for targeted, specific testing, and then only at less than six requests per second.\u003c/p\u003e\n\n\u003cp\u003eAndroid and iOS apps related to these sites are also in scope for these targets. Any reports will need to be fully documented and reproducible. Please provide screenshots, code, and any other information where possible.\u003c/p\u003e\n\n\u003ch2\u003eOut of Scope\u003c/h2\u003e\n\n\u003cp\u003eThe following submission types are considered out of scope:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDenial of service (DoS) attacks\u003c/li\u003e\n\u003cli\u003eFindings as reported by automated tools without additional analysis as to how and what is vulnerable\u003c/li\u003e\n\u003cli\u003eVulnerabilities only affecting users of outdated or unpatched browsers\u003c/li\u003e\n\u003cli\u003eSpam reports\u003c/li\u003e\n\u003cli\u003eTargeted attacks against social media or third party services that OLX use (LinkedIn, Twitter, etc)\u003c/li\u003e\n\u003cli\u003eUser enumeration (accepted risk)\u003c/li\u003e\n\u003cli\u003eDNSSEC issues with minimal or no security implications\u003c/li\u003e\n\u003cli\u003eSSL / TLS issues\u003c/li\u003e\n\u003cli\u003eContent Security Policy (CSP) includes unsafe-inline (is not an issue in itself)\u003c/li\u003e\n\u003cli\u003eSpecific HTTP method enabled with minimal or no security implications\u003c/li\u003e\n\u003cli\u003eCross-Site Request Forgery (CSRF) with minimal or no security implications\u003c/li\u003e\n\u003cli\u003eCSV injection\u003c/li\u003e\n\u003cli\u003eIDN homograph attacks\u003c/li\u003e\n\u003cli\u003eApplication or JavaScript error(s) with minimal or no security implications\u003c/li\u003e\n\u003cli\u003eClickjacking on static website/page\u003c/li\u003e\n\u003cli\u003eCross-Site Tracing (XST)\u003c/li\u003e\n\u003cli\u003eDisclosure of info in robots.txt file\u003c/li\u003e\n\u003cli\u003eLeaking of non-sensitive information on search engine results\u003c/li\u003e\n\u003cli\u003eOpen redirects in the Host header\u003c/li\u003e\n\u003cli\u003eHost header spoofing with minimal or no security implications\u003c/li\u003e\n\u003cli\u003eReverse Tabnabbing\u003c/li\u003e\n\u003cli\u003eServer type/version disclosure\u003c/li\u003e\n\u003cli\u003eWeak Password Policy\u003c/li\u003e\n\u003cli\u003eUser Session management issues (ex: session duration, token reuse, session invalidation on password reset)\u003c/li\u003e\n\u003cli\u003eLack of Jailbreak/Root check/prevention on mobile applications (accepted risk)\u003c/li\u003e\n\u003cli\u003eLack of TLS/SSL Certificate Pinning on mobile applications (accepted risk)\u003c/li\u003e\n\u003cli\u003eBlogs / Wordpress sites hosted on WordPress Engine (WPE)\u003c/li\u003e\n\u003cli\u003eOutdated Library with minimal or no security implications\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003eCredentials can be created via self-signup with a @bugcrowdninja.com email address. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"8dcce1cc-53f0-4e4b-853c-d9804208efcf","name":"In scope targets","targets":[{"id":"ea989e13-4c93-434a-9a5f-b09eb18ccf95","uri":"https://payments.olx.com","name":"payments.olx.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"d9bf1ea8-8f32-449d-8140-ead84d57fc90","sortOrder":0},"sortOrder":0,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"ea989e13-4c93-434a-9a5f-b09eb18ccf95"},{"id":"9dd4899d-3a63-4126-8c83-c1fc1de50c25","name":"Amazon Cloudfront","targetId":"ea989e13-4c93-434a-9a5f-b09eb18ccf95"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"ea989e13-4c93-434a-9a5f-b09eb18ccf95"}],"recentChangeFlags":null},{"id":"9aa8b8e0-f512-49e1-8883-b4a3417911a2","uri":"https://otomoto.pl","name":"*.otomoto.pl","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"6d01f754-ee46-4d12-8306-9cabc5c04206","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"9aa8b8e0-f512-49e1-8883-b4a3417911a2"}],"recentChangeFlags":null},{"id":"535e2962-7dd0-42a8-a07e-8662cdcb2bab","uri":"https://www.olx.pl/","name":"*.olx.pl","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"c256177e-b2b0-4cc4-a9a4-ffc37f72880c","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"535e2962-7dd0-42a8-a07e-8662cdcb2bab"}],"recentChangeFlags":null},{"id":"c65eeac1-c7da-4350-a3a5-0dacf6fdc72c","uri":"https://www.imovirtual.com/","name":"*.imovirtual.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"0932fbce-b8c6-49b4-99e5-578d18c72a1f","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"c65eeac1-c7da-4350-a3a5-0dacf6fdc72c"}],"recentChangeFlags":null},{"id":"8c5433ce-0100-4efa-9827-e892d3a49b6e","uri":"https://www.standvirtual.com/","name":"*.standvirtual.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"4a215950-149c-49f7-9928-f74fadb5c9e7","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"8c5433ce-0100-4efa-9827-e892d3a49b6e"}],"recentChangeFlags":null},{"id":"f7059b2b-9ded-4b1a-b48d-173c15df3ed9","uri":"https://otodom.pl","name":"*.otodom.pl","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"f24d0ea8-c7a6-4cbe-b248-dee8867ab037","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"f7059b2b-9ded-4b1a-b48d-173c15df3ed9"}],"recentChangeFlags":null},{"id":"4fac039a-e13a-45a0-8ba8-de4c6a8055fa","uri":"https://olx.pt","name":"*.olx.pt","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"150e630b-f439-4323-b53c-3c133ce84cc8","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"4fac039a-e13a-45a0-8ba8-de4c6a8055fa"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"b8c43eb1-1dd9-498a-94ee-484ffd138a0e","code":"olx-eu","state":"in_progress","endsAt":null,"bountyId":"ac0d70d0-8f8b-4393-9826-9b1f21a23a2b","startsAt":"2023-01-04T11:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"eCommerce","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/8369/b884/a59963e9/2e3f8d78d38d2cae6783f8ca273e70ce_olx.jpeg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2023-01-04T11:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/olx-eu","changelogs":"/engagements/olx-eu/changelog","submissions":null,"announcements":"/engagements/olx-eu/announcements","hallOfFame":"/engagements/olx-eu/hall_of_fames","crowdstream":null},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/olx-eu/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=olx-eu\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/olx-eu/engagement_subscribers","engagementChangelogsUrl":"/engagements/olx-eu/changelog","publishedAt":"2025-12-11T23:14:20.627Z","engagementChangelogUrl":"/engagements/olx-eu/changelog/a9b2ddee-3d7d-48d0-8a15-7fcb948105d4","createUserFeedbacksUrl":"/engagements/olx-eu/feedbacks","engagementCrowdstreamUrl":null,"acceptedSubmissionsEnabled":false,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}