{"id":"125ef674-f8ed-4b5d-8ff0-988c0dbde0df","engagementId":"28acaae3-74e0-420b-be10-63dda788498d","data":{"brief":{"id":"62f17b96-d91f-4de8-8257-78b86cdf1b2b","name":"Quitelike Vulnerability Disclosure Engagement","tagline":"The meal kit is designed for food lovers, offering low stress and high-quality meals with ever-changing menus, Flybuys, and locally sourced ingredients.","description":"\u003cp\u003eMeal kits including fresh locally sourced ingredients and delicious seasonal recipes to match. Chosen by you. Delivered to your door.\u003c/p\u003e\n\n\u003ch2\u003eRatings\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch2\u003eRules of Engagement\u003c/h2\u003e\n\n\u003cp\u003eRefrain from accessing, modifying, or using data belonging to others. If a vulnerability exposes such data, stop testing, submit a report immediately, and delete all copies of the information.\u003c/p\u003e","industryTagId":"9ed1ce49-a148-438f-92d3-0b8d70b6a8ae","targetsOverview":"\u003cp\u003e\u003cem\u003eIf you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to QuietLike, you can report it to this engagement.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch3\u003eCredentials\u003c/h3\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e. You may register for accounts \u003ca href=\"https://www.quitelike.com/plan/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003eFocus Areas:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://owasp.org/www-project-top-ten/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eOWASP top ten vulnerabilities \u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIDOR and broken access control\u003c/li\u003e\n\u003cli\u003eAccount take over \u003c/li\u003e\n\u003cli\u003eExposure of PII and customer data \u003c/li\u003e\n\u003cli\u003eSecurity control misconfigurations \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eExcluded submission types\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eStored XSS that will impact any account not owned by you.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"de9572e7-4ef0-4b0e-aab4-d5b802924766","name":"In scope","targets":[{"id":"9af40853-d73a-4647-a5fe-8bb0e775a46c","uri":"https://www.quitelike.com/","name":"quitelike.com.au","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"14f417f4-660c-422c-9e23-c6f17ce77db1","sortOrder":0},"sortOrder":0,"tags":[{"id":"4aeb1677-ac84-4afd-827e-054b363ca984","name":"GraphQL","targetId":"9af40853-d73a-4647-a5fe-8bb0e775a46c"},{"id":"624f911d-7e8c-4d56-b523-e7416c1cc319","name":"NextJS","targetId":"9af40853-d73a-4647-a5fe-8bb0e775a46c"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"9af40853-d73a-4647-a5fe-8bb0e775a46c"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"9af40853-d73a-4647-a5fe-8bb0e775a46c"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null},{"id":"3c3d0953-ad2d-4b66-8ec1-cd6d327c0451","name":"Out of scope","targets":[{"id":"09c3b971-ab3b-4d7b-8d29-ff1059464c4f","uri":"","name":"Third party providers and services","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"736ca8ea-4b4e-4801-836d-6118712ecdfa","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"9318f88a-2dda-4b84-a358-e66233981ec8","uri":"","name":"Orders - Any orders made cannot be refunded.","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f56cd171-36e6-4b70-8b2c-9b3b2bce4d49","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eQuiteLike utilises and hosts several third party providers and services which may be listed as subdomains of those which are in scope. We cannot authorise testing against these systems. If unclear please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eShopify GraphQL admin or Storefront API:\n\n\u003cul\u003e\n\u003cli\u003eGraphQL admin or storefront APs\u003c/li\u003e\n\u003cli\u003eSubmarine Subscription\u003c/li\u003e\n\u003cli\u003eYotpo Services \u0026amp; Endpoints\u003c/li\u003e\n\u003cli\u003eGorgias CRM / Customer Service Chatbot and API\u003c/li\u003e\n\u003cli\u003eKlaviyo CRM and Marketing\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003eApicbase ERP and calls to Apicbase endpoints\u003c/li\u003e\n\u003cli\u003ePayments - Stripe\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"28acaae3-74e0-420b-be10-63dda788498d","code":"quitelike-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"cf977740-09f3-4e9a-b198-06aa3418b467","startsAt":"2025-03-11T23:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Retail","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/9b43/ce1e/0cd68f44/cb6cb9b8ed21c546e22f81d11237db94_quitelike_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-03-11T23:00:00.046Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/quitelike-vdp-pro","changelogs":"/engagements/quitelike-vdp-pro/changelog","submissions":null,"announcements":"/engagements/quitelike-vdp-pro/announcements","hallOfFame":"/engagements/quitelike-vdp-pro/hall_of_fames","crowdstream":"/engagements/quitelike-vdp-pro/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/quitelike-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=quitelike-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/quitelike-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/quitelike-vdp-pro/changelog","publishedAt":"2025-04-03T19:24:59.082Z","engagementChangelogUrl":"/engagements/quitelike-vdp-pro/changelog/125ef674-f8ed-4b5d-8ff0-988c0dbde0df","createUserFeedbacksUrl":"/engagements/quitelike-vdp-pro/feedbacks","engagementCrowdstreamUrl":"/engagements/quitelike-vdp-pro/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}