{"id":"766c37c3-6b66-4f52-bb75-89bfd519f6d3","engagementId":"2871b741-3465-4893-a213-9e2c24fcc7f3","data":{"brief":{"id":"93ff1064-8304-4be4-9b94-8a6b457e1cd0","name":"QuintoAndar Managed Bug Bounty Engagement","tagline":"The QuintoAndar Group is the leading real estate ecosystem in Latin America, with a presence in Argentina, Brazil, Ecuador, Mexico, Panama and Peru. With 10 years of experience, Grupo QuintoAndar aims to help people love the place where they live.","description":"\u003cp\u003eNo technology is perfect and QuintoAndar believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our assets. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch4\u003ePlease note: Only Critical (P1), Severe (P2), Moderate (P3), submissions will be rewarded. P4 \u0026amp; P5 findings will be marked as Low and Informational (respectively), but no reward will be paid.\u003c/h4\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003ch3\u003eImportant Notes\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of QuintoAndar not listed in the targets section is out of scope. This includes any/all subdomains not listed above. In general, services hosted for Quinto Andar by third parties are out of scope. We do not condone or grant permission to test on third-party assets. \u003c/li\u003e\n\u003cli\u003eSubmissions containing leaked credentials will be addressed on a case-by-case basis to determine whether or not there is a security impact.\u003c/li\u003e\n\u003cli\u003eAll vulnerabilities that require social engineering to be successfully exploited will be treated as P4.\u003c/li\u003e\n\u003cli\u003eReports involving the same path with different methods or subpaths will be evaluated on a case-by-case basis. If the vulnerabilities share the same root cause or require a common fix, they may be considered duplicates and not separately eligible for rewards.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eScenario\u003c/th\u003e\n\u003cth\u003eExample\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eThat may be considered the same root cause\u003c/td\u003e\n\u003ctd\u003eGET /api/user/info and GET /api/user/settings\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eThat may not be considered from the same root cause\u003c/td\u003e\n\u003ctd\u003eGET /api/user/info and POST /api/user/info\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eAccess\u003c/h3\u003e\n\n\u003cp\u003eAll of the targets are accessible via the public internet. Please use markdown:\u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eIdentifier\u003c/th\u003e\n\u003cth\u003eHeader\u003c/th\u003e\n\u003cth\u003eExample\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eUsername\u003c/td\u003e\n\u003ctd\u003eX-Bug-Bounty: Bugcrowd-\u0026lt;Username\u0026gt;\u003c/td\u003e\n\u003ctd\u003eX-Bug-Bounty: Bugcrowd-proresearcher\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut of Scope Vulnerabilities -\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eIssues considered out of scope include:\u003c/li\u003e\n\u003cli\u003eVulnerabilities that allow unauthorized access but are intrinsic to the intended functionality of our systems based on established business rules, and block permissions from our operation.\u003c/li\u003e\n\u003cli\u003eCredential leakages from end users that did not result from a failure of QuintoAndar's resources.\u003c/li\u003e\n\u003cli\u003eSocial engineering (e.g., phishing, vishing, smishing) is prohibited.\u003c/li\u003e\n\u003cli\u003eCross-Site Request Forgery (CSRF) on unauthenticated forms.\u003c/li\u003e\n\u003cli\u003eAttacks requiring MITM or physical access to a user's device.\u003c/li\u003e\n\u003cli\u003ePreviously known vulnerable libraries without a working Proof of Concept.\u003c/li\u003e\n\u003cli\u003eComma-Separated Values (CSV) injection without demonstrating a vulnerability.\u003c/li\u003e\n\u003cli\u003eMissing best practices in SSL/TLS configuration.\u003c/li\u003e\n\u003cli\u003eAny activity that could lead to the disruption of our service (DoS).\u003c/li\u003e\n\u003cli\u003eContent spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS\u003c/li\u003e\n\u003cli\u003eRate limiting or brute force issues on non-authentication endpoints\u003c/li\u003e\n\u003cli\u003eMissing best practices in Content Security Policy.\u003c/li\u003e\n\u003cli\u003eMissing HttpOnly or Secure flags on cookies\u003c/li\u003e\n\u003cli\u003eMissing email best practices (Invalid, incomplete, or missing SPF/DKIM/DMARC records, etc.)\u003c/li\u003e\n\u003cli\u003eVulnerabilities only affect users of outdated or unpatched browsers (Less than 2 stable versions behind the latest released stable version)\u003c/li\u003e\n\u003cli\u003eSoftware version disclosure, Banner identification issues, and Descriptive error messages or headers (e.g., stack traces, application or server errors) will not be eligible for a reward.\u003c/li\u003e\n\u003cli\u003eTabnabbing\u003c/li\u003e\n\u003cli\u003eSubdomain takeover on subdomains that aren't in scope\u003c/li\u003e\n\u003cli\u003eOpen redirect (unless an additional security impact can be demonstrated)\u003c/li\u003e\n\u003cli\u003eIssues that require unlikely user interaction will not be eligible for a reward.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eCredentials:\u003c/h2\u003e\n\n\u003cp\u003ePlease use your bugcrowdninja email address if setting up specific user accounts.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good-faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ecreate a ticket with Bugcrowd Support\u003c/a\u003e for clarification before proceeding.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"7906771f-43e8-41f2-bbfe-a9211c26b8d2","name":"In Scope","targets":[{"id":"af9be302-d6b3-40d5-a880-454f9e3d116b","uri":"https://www.quintoandar.com.br/*","name":"https://www.quintoandar.com.br/*","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"22b803ba-ac26-44ed-bf96-911084ec4783","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"af9be302-d6b3-40d5-a880-454f9e3d116b"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"af9be302-d6b3-40d5-a880-454f9e3d116b"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"af9be302-d6b3-40d5-a880-454f9e3d116b"}],"recentChangeFlags":null},{"id":"f9134138-5c69-4d24-84df-6c126e018b45","uri":"https://www.user.quintoandar.com.br/admin/*","name":"https://user.quintoandar.com.br/admin/*","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5d558bb5-e522-4729-acef-75e0bed49a21","sortOrder":1},"sortOrder":1,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"f9134138-5c69-4d24-84df-6c126e018b45"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"f9134138-5c69-4d24-84df-6c126e018b45"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"f9134138-5c69-4d24-84df-6c126e018b45"}],"recentChangeFlags":null},{"id":"31f8bb22-ed88-4772-93ad-6dd5bad3ff66","uri":"https://www.financeiro.quintoandar.com.br/*","name":"https://financeiro.quintoandar.com.br/*","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2235362c-1c09-4593-ad85-abdc00e6f3e8","sortOrder":2},"sortOrder":2,"tags":[{"id":"578f7631-aa18-4ca8-b7a6-9f90b2a2b964","name":"Clojure","targetId":"31f8bb22-ed88-4772-93ad-6dd5bad3ff66"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"31f8bb22-ed88-4772-93ad-6dd5bad3ff66"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"31f8bb22-ed88-4772-93ad-6dd5bad3ff66"}],"recentChangeFlags":null},{"id":"d78d9b0c-e050-41dc-a7ba-b3871d3b4975","uri":"https://apigw.prod.quintoandar.com.br/pixar-api/*","name":"https://apigw.prod.quintoandar.com.br/pixar-api/*","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"57cd2174-b819-47a4-b85a-d26fa643d2f9","sortOrder":3},"sortOrder":3,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"d78d9b0c-e050-41dc-a7ba-b3871d3b4975"},{"id":"578f7631-aa18-4ca8-b7a6-9f90b2a2b964","name":"Clojure","targetId":"d78d9b0c-e050-41dc-a7ba-b3871d3b4975"}],"recentChangeFlags":null},{"id":"6b4a4105-adc0-4976-9d23-10d95dfa7486","uri":"https://finance.quintoandar.com.br/*","name":"https://finance.quintoandar.com.br/*","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1b9cda91-a603-451e-a54c-f1f65891a58e","sortOrder":4},"sortOrder":4,"tags":[{"id":"33a7c027-8a7e-4564-8330-cb149ab4352e","name":"TypeScript","targetId":"6b4a4105-adc0-4976-9d23-10d95dfa7486"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"6b4a4105-adc0-4976-9d23-10d95dfa7486"}],"recentChangeFlags":null},{"id":"76a52788-5fed-4523-b125-047ba03270e5","uri":"https://trato-feito-api.quintoandar.com.br/*","name":"https://trato-feito-api.quintoandar.com.br/*","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ef72bcda-49e6-46ea-999c-db91a83157da","sortOrder":5},"sortOrder":5,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"76a52788-5fed-4523-b125-047ba03270e5"},{"id":"578f7631-aa18-4ca8-b7a6-9f90b2a2b964","name":"Clojure","targetId":"76a52788-5fed-4523-b125-047ba03270e5"}],"recentChangeFlags":null},{"id":"dd941058-1ba9-4cd3-8d1e-0265db4db1a2","uri":"https://apigw.prod.quintoandar.com.br/checkout-api/*","name":"https://apigw.prod.quintoandar.com.br/checkout-api/*","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"1532e32f-1703-4632-8aeb-6d9a621c3140","sortOrder":6},"sortOrder":6,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"dd941058-1ba9-4cd3-8d1e-0265db4db1a2"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"dd941058-1ba9-4cd3-8d1e-0265db4db1a2"}],"recentChangeFlags":null},{"id":"a880261f-50ee-4058-b9f9-9ee99ac58829","uri":"https://apigw.prod.quintoandar.com.br/sales-flow-api/*","name":"https://apigw.prod.quintoandar.com.br/sales-flow-api/*","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"87b4b159-c6e4-4a6e-8458-76454b870acf","sortOrder":8},"sortOrder":8,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"a880261f-50ee-4058-b9f9-9ee99ac58829"},{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"a880261f-50ee-4058-b9f9-9ee99ac58829"}],"recentChangeFlags":null},{"id":"540455c3-9af8-4c07-b405-ab9715fdbbfe","uri":"https://apigw.prod.quintoandar.com.br/nazare-api/*","name":"https://apigw.prod.quintoandar.com.br/nazare-api/*","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ce54a610-750c-41cf-9710-46f199d592d3","sortOrder":9},"sortOrder":9,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"540455c3-9af8-4c07-b405-ab9715fdbbfe"},{"id":"578f7631-aa18-4ca8-b7a6-9f90b2a2b964","name":"Clojure","targetId":"540455c3-9af8-4c07-b405-ab9715fdbbfe"}],"recentChangeFlags":null},{"id":"dcf40847-ee8a-4f8b-84d3-8f1bd71e5748","uri":"https://apigw.prod.quintoandar.com.br/rental-guarantee-api/*","name":"https://apigw.prod.quintoandar.com.br/rental-guarantee-api/*","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5528d222-e9c9-4d6c-b689-a4014dee8d80","sortOrder":10},"sortOrder":10,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"dcf40847-ee8a-4f8b-84d3-8f1bd71e5748"},{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"dcf40847-ee8a-4f8b-84d3-8f1bd71e5748"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"559098de-c0b2-4055-a680-5981f8f012bd","p1MaxCents":100000,"p1MinCents":50000,"p2MaxCents":50000,"p2MinCents":30000,"p3MaxCents":30000,"p3MinCents":10000,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eInformation about the targets can be found in the resource section.\u003c/p\u003e","rewardRangeData":{"1":{"min":500,"max":1000},"2":{"min":300,"max":500},"3":{"min":100,"max":300},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[{"id":"fd36c5d0-ec8c-49df-b939-7e11199aeee5","attachmentPath":"https://bugcrowd.com/engagements/quintoandar/attachments/fd36c5d0-ec8c-49df-b939-7e11199aeee5","name":"Quinto_Andar_Target_Info.pdf","filename":"Quinto_Andar_Target_Info.pdf","description":null,"icon":"fileOther","size":34205,"sizeLabel":"33.4 KB","uploadedAt":"14 Apr 2025","fileType":"Document","embedUrl":"https://bugcrowd.com/engagements/quintoandar/attachments/fd36c5d0-ec8c-49df-b939-7e11199aeee5"}],"engagement":{"id":"2871b741-3465-4893-a213-9e2c24fcc7f3","code":"quintoandar","state":"in_progress","endsAt":null,"bountyId":"8a069190-924a-402d-9a0d-b5ba0f54ec4e","startsAt":"2024-07-02T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/0fde/c5b3/e8391126/6e7e6fbaa0708c72c2bb28854e3a6826_quintoandar_com_br_logo.jpeg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2024-07-02T18:00:00.034Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/quintoandar","changelogs":"/engagements/quintoandar/changelog","submissions":null,"announcements":"/engagements/quintoandar/announcements","hallOfFame":"/engagements/quintoandar/hall_of_fames","crowdstream":"/engagements/quintoandar/crowdstream"},"announcementsCount":10,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/quintoandar/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=quintoandar\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/quintoandar/engagement_subscribers","engagementChangelogsUrl":"/engagements/quintoandar/changelog","publishedAt":"2026-04-28T20:50:51.109Z","engagementChangelogUrl":"/engagements/quintoandar/changelog/766c37c3-6b66-4f52-bb75-89bfd519f6d3","createUserFeedbacksUrl":"/engagements/quintoandar/feedbacks","engagementCrowdstreamUrl":"/engagements/quintoandar/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}