{"id":"2392574e-a42e-4703-bde5-d1ba5d23b325","engagementId":"15d2ee89-6e52-409c-9a4f-31eb05040a55","data":{"brief":{"id":"cf3910fd-d89a-4896-862c-c15c3c482fcf","name":"Plusgrade Loyalty Public Program","tagline":"Plusgrade powers the global travel industry with ancillary offerings and loyalty expertise to create incredible travel experiences and new revenue opportunities.","description":"\u003cp\u003eNo technology is perfect and Plusgrade believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We care about our partners' information security, and we're ready to work with security researchers to improve the security of our services. Plusgrade believes that ethical security research performed in good-faith provides an invaluable public service.\u003c/p\u003e\n\n\u003cp\u003eWe are excited for you to participate as a security researcher to help us identify vulnerabilities in our web applications.\u003c/p\u003e\n\n\u003cp\u003eGood luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch2\u003eProgram Rules:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eIMPORTANT: Applications within the same target group of this engagement may share the same codebase. Vulnerability reports submitted on the same vulnerability across different endpoints belonging to the same Plusgrade scope grouping are not eligible for multiple rewards. Multiple reports on the same vulnerability will be considered duplicates. Please submit a single report.\u003c/strong\u003e\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003e\u003cstrong\u003e\u003cem\u003eTesting is only authorized on the targets listed as In-Scope. Any domain/property of Plusgrade not listed in the targets section, or the additional resources tab, is out of scope.  Any submissions that are not on the in-scope targets will be marked as out of scope and will not be eligible for monetary or points-based compensation.\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003e\u003cem\u003ePlease be cautious with the use of vulnerability scanners on this program. Custom scripts and fuzzing tools are permitted, however if using an automated tool or script please throttle traffic to six requests per second or less.\u003c/em\u003e\u003c/strong\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eCredentials:\u003c/h2\u003e\n\n\u003cp\u003ePlusgrade does not provide credentials or authorization links for security research purposes. To perform authenticated testing, researchers are expected to already have, or to obtain, a legitimate \u0026amp; verified login created in their own name (not leaked or compromised) from the associated loyalty program, or be in possession of a valid upgrade authorization link. Please abide by the rules of the loyalty program in question, and bear in mind that loyalty programs may limit the use of multiple accounts for the same individual. Unauthenticated testing may be performed against in-scope targets without a loyalty account or upgrade authorization link.\u003c/p\u003e\n\n\u003cp\u003eIf you encounter leaked or compromised credentials for in scope targets, please do not use them, or attempt to use them.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eFocus Areas:\u003c/h2\u003e\n\n\u003cp\u003eWe identified the following focus areas to facilitate your testing and would like you to report your efforts around these (Please note you’re free and encouraged to test outside of the following, these are just a few areas that are particularly important to us):\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eRemote code execution (RCE)\u003c/li\u003e\n\u003cli\u003eInjection attacks (SQL injection, Command injection, XML injection, CRLF injection)\u003c/li\u003e\n\u003cli\u003eXML external entity (XXE)\u003c/li\u003e\n\u003cli\u003eCross site scripting (XSS)\u003c/li\u003e\n\u003cli\u003eServer side request forgery (SSRF)\u003c/li\u003e\n\u003cli\u003eCross site request forgery (CSRF)\u003c/li\u003e\n\u003cli\u003eDirectory traversal - local file inclusion\u003c/li\u003e\n\u003cli\u003eAuthentication/authorization bypass\u003c/li\u003e\n\u003cli\u003ePrivilege escalation\u003c/li\u003e\n\u003cli\u003eInsecure direct object reference (IDOR)\u003c/li\u003e\n\u003cli\u003eSite and server misconfigurations\u003c/li\u003e\n\u003cli\u003eWeb cache deception\u003c/li\u003e\n\u003cli\u003eCross-Origin Resource Sharing misconfiguration (CORS)\u003c/li\u003e\n\u003cli\u003eOpen redirect\u003c/li\u003e\n\u003cli\u003eInformation disclosure\u003c/li\u003e\n\u003cli\u003eRequest smuggling\u003c/li\u003e\n\u003cli\u003eMixed content\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut-of-Scope Areas\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eCorporate email and file storage\u003c/li\u003e\n\u003cli\u003eCorporate VPN\u003c/li\u003e\n\u003cli\u003e3rd party applications and services\u003c/li\u003e\n\u003cli\u003eSPF, DKIM and DMARC submissions\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eExpectations\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eMake a good-faith effort to avoid harm to Plusgrade Inc, our subsidiaries, our customers, and our end-users, including, but not limited to: privacy violations, destruction of data, and interruption or degradation of our services.\u003c/li\u003e\n\u003cli\u003eDo not access or attempt to access Plusgrade offices, data centers, or user accounts.\u003c/li\u003e\n\u003cli\u003eDo not test for spam, perform phishing, social engineer, or intentionally cause denial of service issues for Plusgrade services.\u003c/li\u003e\n\u003cli\u003eDo not access or attempt to access our partner's systems, data centers, user accounts, or attempt other forms of penetration testing without the direct, written approval of the system owner.\u003c/li\u003e\n\u003cli\u003eComply with all applicable laws and regulations; do not disrupt or compromise any data that is not your own, or further exploit a confirmed vulnerability.\u003c/li\u003e\n\u003cli\u003eIf a vulnerability provides unintended access to data, limit the amount of data you access to the minimum required to demonstrate a proof of concept. After Plusgrade validates your report, properly dispose of all copies of the data.\u003c/li\u003e\n\u003cli\u003ePlease do not cache any submission or finding publicly on sites such as the Internet Archive.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen making submissions that involve deep links, magic links or personalized links, you must include the details on how the link was obtained.  Failure to do so may result in the submission being ineligible for reward.\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eSubmissions that uniquely involve the finding of deep links, magic links or personalized links in search engines, archives or other repositories are only eligible for informational (P5) submission.  To qualify for other rating levels, the researcher must demonstrate how the link ended up in the search engine, archive or repository.  Only active links will be considered.  Expired links do not qualify.\u003c/strong\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eDisclosure\u003c/h2\u003e\n\n\u003cp\u003eThis program or engagement does not allow disclosure. You may not release information about vulnerabilities found in this program or engagement to the public.\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"0c9417bd-8758-4b29-9ffe-f499f8f94fd7","name":"Loyalty","targets":[{"id":"ad24781a-4885-474c-b2ee-4b76bb5a6e07","uri":"","name":"*.points.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"809f7525-7e13-45db-82cb-6beda179675b","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"ad24781a-4885-474c-b2ee-4b76bb5a6e07"},{"id":"8442481b-5110-4077-bdd1-54fd464584f6","name":"Go","targetId":"ad24781a-4885-474c-b2ee-4b76bb5a6e07"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"ad24781a-4885-474c-b2ee-4b76bb5a6e07"}],"recentChangeFlags":null},{"id":"c0beef45-751a-4992-8dd6-b6e284a1f733","uri":"","name":"Additional Loyalty scope included under resources tab","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"56ee5d56-d507-42aa-85c4-2bfd408d373d","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"e4fd1eb8-8fd1-4f75-9d72-4f2a43ab5979","p1MaxCents":500000,"p1MinCents":420000,"p2MaxCents":250000,"p2MinCents":200000,"p3MaxCents":60000,"p3MinCents":45000,"p4MaxCents":20000,"p4MinCents":15000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eThis target group focuses on loyalty programs for the global travel \u0026amp; hospitality industry.\u003c/p\u003e","rewardRangeData":{"1":{"min":4200,"max":5000},"2":{"min":2000,"max":2500},"3":{"min":450,"max":600},"4":{"min":150,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"26e8ee12-d5e8-4f0e-9b4d-6a4f02a9f5ff","name":"Out-Of-Scope","targets":[{"id":"0509297f-7aca-4b0b-a9cb-a7b272f52e8d","uri":"","name":"Partner Website \u0026 Applications","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"16a073aa-8efb-4c08-9ac5-697d5a5c8f80","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"5afb6109-34b6-442f-a12d-07321b2936e8","uri":"","name":"Anything not explicitly listed as in-scope","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"92ddbca4-1113-4f68-8469-9664b9b93592","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eWe realize that it can be confusing where Plusgrade\u0026#39;s services end and our partner\u0026#39;s service begin (and vice-versa). We often display branded pages on behalf of our partners. \u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[{"id":"fa5e3dd9-cd79-4b0e-8856-ca00e0534981","attachmentPath":"https://bugcrowd.com/engagements/plusgrade-mbb-public/attachments/fa5e3dd9-cd79-4b0e-8856-ca00e0534981","name":"Loyalty-Vanity-Targets.txt","filename":"Loyalty-Vanity-Targets.txt","description":null,"icon":"fileOther","size":761,"sizeLabel":"761 Bytes","uploadedAt":"16 Oct 2024","fileType":"Document","embedUrl":"https://bugcrowd.com/engagements/plusgrade-mbb-public/attachments/fa5e3dd9-cd79-4b0e-8856-ca00e0534981"}],"engagement":{"id":"15d2ee89-6e52-409c-9a4f-31eb05040a55","code":"plusgrade-mbb-public","state":"in_progress","endsAt":null,"bountyId":"adb7a6fc-3bcf-4096-8a9f-6a6be74a2c31","startsAt":"2024-07-01T00:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/187f/368f/deac4e48/bfab2decdcd9127b3b0ac882c43caf19_plusgrade_logo.jpeg","logoBackgroundColor":"#2a2d40","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-05-07T16:57:50.666Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/plusgrade-mbb-public","changelogs":"/engagements/plusgrade-mbb-public/changelog","submissions":null,"announcements":"/engagements/plusgrade-mbb-public/announcements","hallOfFame":"/engagements/plusgrade-mbb-public/hall_of_fames","crowdstream":"/engagements/plusgrade-mbb-public/crowdstream"},"announcementsCount":4,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/plusgrade-mbb-public/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=plusgrade-mbb-public\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/plusgrade-mbb-public/engagement_subscribers","engagementChangelogsUrl":"/engagements/plusgrade-mbb-public/changelog","publishedAt":"2025-10-30T22:52:33.905Z","engagementChangelogUrl":"/engagements/plusgrade-mbb-public/changelog/2392574e-a42e-4703-bde5-d1ba5d23b325","createUserFeedbacksUrl":"/engagements/plusgrade-mbb-public/feedbacks","engagementCrowdstreamUrl":"/engagements/plusgrade-mbb-public/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}