{"id":"d490e919-ad94-4021-9936-c2606427777c","engagementId":"bc9e5f7e-c3ad-402c-8089-7368ea077e28","data":{"brief":{"id":"b6f973fb-f502-44e1-b01f-68d12123ff37","name":"SeatGeek Vulnerability Disclosure Engagement","tagline":"SeatGeek is transforming the way fans buy and sell their tickets to their favorite live events across sports, music, and theater.","description":"\u003cp\u003eNo technology is perfect and SeatGeek believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our assets. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003cp\u003eWhen submitting a report to SeatGeek, provide as much information as possible about the potential issue you have discovered. The more information you provide, the quicker SeatGeek will be able to validate the issue. Please review the brief below for details on testing.\u003c/p\u003e\n\n\u003ch2\u003eRatings\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of SeatGeek not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to SeatGeek, you can report it here. However, be aware that it is ineligible for points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eFocus Areas:\u003c/h2\u003e\n\n\u003cp\u003eWe’d like to focus specifically on our website and the API at this time. Any general high severity web application vulnerabilities will result in a high severity report.\u003c/p\u003e\n\n\u003cp\u003eIn addition, these focus areas will also result in a high severity report:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eCheckout and payment flows\u003c/strong\u003e: Manipulation of the final purchase amount in the checkout and/or payment flows through any attack vector (including manipulating coupons).\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eArbitrary and significant data access\u003c/strong\u003e: Any attack that allows for arbitrary \u003cstrong\u003eand\u003c/strong\u003e significant data access without requiring unusual or obscure user interaction.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess and Credentials:\u003c/h2\u003e\n\n\u003ch4\u003eCreating accounts\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eTo gain access to the application, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e. You may register for accounts here: \u003ca href=\"https://seatgeek.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://seatgeek.com/\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eReporting Structure\u003c/h2\u003e\n\n\u003cp\u003ePlease submit identified vulnerabilities using the below structure:\u003c/p\u003e\n\n\u003cp\u003e• Issue Name/Title of the Vulnerability\u003cbr\u003e\n• Description of the vulnerability identified\u003cbr\u003e\n• Steps to Reproduce the vulnerability along with Screenshots\u003cbr\u003e\n• Impacted/Affected URL/Domain\u003c/p\u003e\n\n\u003ch4\u003eTest Events\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eFor testing we have these dedicated events for bug hunting which can be reviewed below: \n\n\u003cul\u003e\n\u003cli\u003e\n\u003ca href=\"https://seatgeek.com/silver-snakes-tickets/soccer/2026-01-02-7-pm/5684987?preview_token=OKBzQbJlKo\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://seatgeek.com/silver-snakes-tickets/soccer/2026-01-02-7-pm/5684987?preview_token=OKBzQbJlKo\u003c/a\u003e\n\n\u003cul\u003e\n\u003cli\u003eUse \"BUGBOUNTYFREE\" or \"BUGBOUNTY\" as \u003ca href=\"https://support.seatgeek.com/hc/en-us/articles/4415792979731-What-is-an-Access-Code\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ean access code\u003c/a\u003e for the event for select tickets to become $0.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003ca href=\"https://seatgeek.com/silver-snakes-tickets/soccer/2026-01-03-7-pm/5723979?preview_token=eKbL2y1GRg\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://seatgeek.com/silver-snakes-tickets/soccer/2026-01-03-7-pm/5723979?preview_token=eKbL2y1GRg\u003c/a\u003e (Presale)\n\n\u003cul\u003e\n\u003cli\u003eUse the presale code \"BUGBOUNTY\" for access to the presale and for tickets to become $0.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003ePlease note that the code \u003ccode\u003eBUGBOUNTY\u003c/code\u003e can be used interchangeably as an access or promo code but either case will result in tickets being $0.\u003c/p\u003e\n\n\u003ch4\u003eAPI Documentation\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eWe currently have documentation for our \u003ca href=\"https://api.seatgeek.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAPI\u003c/a\u003e hosted at \u003ca href=\"https://developer.seatgeek.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003edeveloper.seatgeek.com\u003c/a\u003e\n\n\u003cul\u003e\n\u003cli\u003ePlease use your @bugcrowdninja.com email to register. You should be granted access to the documentation.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDo not test on \u003ca href=\"https://developer.seatgeek.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003edeveloper.seatgeek.com\u003c/a\u003e, this is not in scope.\u003c/strong\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eTest Requests\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen testing and to the best of your abilities, please add a “X-SG-Bug-Bounty” header with your username. Testing without this header might result in blocking of your account or IP address.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut-of-Scope\u003c/h2\u003e\n\n\u003cp\u003eWhen reporting vulnerabilities, please consider (1) attack scenario/exploitability, and (2) the security impact of the bug. All P5 severity bugs on \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ethe Bugcrowd VRT\u003c/a\u003e are considered out of scope as well as the following issues:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eCross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive actions\u003c/li\u003e\n\u003cli\u003eAttacks requiring MITM or physical access to a user's device\u003c/li\u003e\n\u003cli\u003ePreviously known vulnerable libraries without a working Proof of Concept\u003c/li\u003e\n\u003cli\u003eComma Separated Values (CSV) injection without demonstrating a vulnerability\u003c/li\u003e\n\u003cli\u003eAny activity that could lead to the disruption of our service, our 3rd party integrations, and service providers (e.g. DoS)\u003c/li\u003e\n\u003cli\u003eContent spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS\u003c/li\u003e\n\u003cli\u003eMissing best practices in Content Security Policy\u003c/li\u003e\n\u003cli\u003eMissing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)\u003c/li\u003e\n\u003cli\u003eVulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]\u003c/li\u003e\n\u003cli\u003eSoftware version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors)\u003c/li\u003e\n\u003cli\u003ePublic Zero-day vulnerabilities that have had an official patch for less than 1 month will be awarded on a case-by-case basis\u003c/li\u003e\n\u003cli\u003eOpen redirect - unless an additional security impact can be demonstrated\u003c/li\u003e\n\u003cli\u003eIssues that require unlikely user interaction\u003c/li\u003e\n\u003cli\u003eReports from automated tools or scans\u003c/li\u003e\n\u003cli\u003eAny report that discusses how you can learn whether a given username or email address has a SeatGeek account\u003c/li\u003e\n\u003cli\u003eThird-party hosted services\u003c/li\u003e\n\u003cli\u003eIP/Port Scanning via SeatGeek services unless you are able to hit private IPs or SeatGeek servers\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eLegal\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou must comply with all applicable federal, state, and local laws in connection with your security research activities or other participation in this vulnerability disclosure program.\u003c/li\u003e\n\u003cli\u003eYou agree that You shall not, without the prior written consent of SeatGeek in each instance (i) use in advertising, publicity or otherwise the name of SeatGeek or its affiliates or any trade name, trademark, trade device, service mark, symbol or any abbreviation, contraction or simulation thereof owned by SeatGeek or its affiliates, or (ii) represent, directly or indirectly, any service or work provided by You as approved or endorsed by SeatGeek or its affiliates.\u003c/li\u003e\n\u003cli\u003eYou agree that any and all information acquired or accessed by You as part of this exercise is confidential to SeatGeek and You shall hold such confidential information in strict confidence and shall not copy, reproduce, sell, assign, license, market, transfer or otherwise dispose of, give or disclose such information to third parties or use such information for any purposes other than for the performance of your work.\u003c/li\u003e\n\u003cli\u003eYou acknowledge and agree that any and all information you encounter is owned by SeatGeek or its third-party providers, clients or customers. You have no rights, title or ownership to any information that you may encounter.\u003c/li\u003e\n\u003cli\u003eSeatGeek may modify the terms of this policy or terminate the policy at any time.\u003c/li\u003e\n\u003cli\u003eBy clicking Submit Report, you consent to Your Information being transferred to and stored in the United States and acknowledge that you have read and accepted the Terms, Privacy Policy and Disclosure Guidelines presented to you when you created your account.\u003c/li\u003e\n\u003cli\u003ePlease use your own account for testing or research purposes. Do not attempt to gain access to another user’s account or confidential information.\u003c/li\u003e\n\u003cli\u003ePlease do not test for spam, social engineering or denial of service issues. Your testing must not violate any law, or disrupt or compromise any data that is not your own.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch2\u003eEligibility for Participation\u003c/h2\u003e\n\n\u003cp\u003eYou are responsible for complying with any applicable laws. You are not eligible to participate in this program if you are currently an employee of SeatGeek or any of its subsidiaries. Reports from former employees, the immediate family of current employees, or other associates of SeatGeek that may present a conflict of interest of the goals of the program will be more thoroughly reviewed and may not qualify for the stated awards at SeatGeek's discretion.\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"8dfd9264-1d98-450f-b45c-ba7c250bba13","name":"In scope","targets":[{"id":"a0b75481-9094-49f2-9920-60043d305ed8","uri":"https://seatgeek.com/","name":"https://seatgeek.com/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"9bb3674f-28a1-4a5d-900e-43497ac60caf","sortOrder":0},"sortOrder":0,"tags":[{"id":"624f911d-7e8c-4d56-b523-e7416c1cc319","name":"NextJS","targetId":"a0b75481-9094-49f2-9920-60043d305ed8"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"a0b75481-9094-49f2-9920-60043d305ed8"},{"id":"95cf953e-85ee-42c2-9123-09d81bfe7ba9","name":"PostgreSQL","targetId":"a0b75481-9094-49f2-9920-60043d305ed8"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"a0b75481-9094-49f2-9920-60043d305ed8"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"a0b75481-9094-49f2-9920-60043d305ed8"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"a0b75481-9094-49f2-9920-60043d305ed8"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"a0b75481-9094-49f2-9920-60043d305ed8"}],"recentChangeFlags":null},{"id":"82b886bc-883a-47ec-854e-b8a03460cdf6","uri":"https://api.seatgeek.com/","name":"https://api.seatgeek.com/","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2b3a6deb-203f-4702-b252-9e8ae270e2a5","sortOrder":1},"sortOrder":1,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"82b886bc-883a-47ec-854e-b8a03460cdf6"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"82b886bc-883a-47ec-854e-b8a03460cdf6"},{"id":"95cf953e-85ee-42c2-9123-09d81bfe7ba9","name":"PostgreSQL","targetId":"82b886bc-883a-47ec-854e-b8a03460cdf6"},{"id":"f21f7de7-31b4-4cc8-89a4-39c9eb6b7345","name":"Python","targetId":"82b886bc-883a-47ec-854e-b8a03460cdf6"}],"recentChangeFlags":null},{"id":"1442bdfc-e13e-46a8-bfb3-592e1b9829b1","uri":"https://seatgeek.com/silver-snakes-tickets/soccer/2026-01-02-7-pm/5684987?preview_token=OKBzQbJlKo","name":"SeatGeek Test Event","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"74bad339-ffce-414d-90ef-15ea8b32a45b","sortOrder":2},"sortOrder":2,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"1442bdfc-e13e-46a8-bfb3-592e1b9829b1"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":"\u003ch2\u003eTarget Information:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eFor this engagement you are testing ticket marketplace \u003ca href=\"https://seatgeek.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSeatGeek\u003c/a\u003e. In scope are their \u003ca href=\"https://seatgeek.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003emain web application\u003c/a\u003e, \u003ca href=\"https://api.seatgeek.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAPI\u003c/a\u003e, and \u003ca href=\"https://seatgeek.com/bug-bounty-tickets/soccer/2026-01-02-7-pm/5684987\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ea test event for purchasing tickets (details below)\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eYou are testing in production.\u003c/strong\u003e Please take care to ensure your testing is non disruptive to either standard users or the site itself. You can do this by ensuring your testing only takes place on accounts you control and the test event.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e","rewardRangeData":{},"recentChangeFlags":null},{"id":"72c950fa-ccca-4e6f-ae8a-041ee9f895e8","name":"Out of scope","targets":[{"id":"d3211b7b-cf0e-4078-937b-351eb7e301d2","uri":"","name":"https://developer.seatgeek.com/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d3878fca-c01a-4d58-84d5-24c51dfe2d28","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"bc9e5f7e-c3ad-402c-8089-7368ea077e28","code":"seatgeek-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"5c6798df-79ed-43e7-aec7-bc4e4e2e8941","startsAt":"2025-06-10T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/1826/3ba7/1b3a5c91/c9b9423963f30c81495ba9627069827c_App_Icon_-_iOS_Cropped.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-06-10T18:00:01.976Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/seatgeek-vdp-pro","changelogs":"/engagements/seatgeek-vdp-pro/changelog","submissions":null,"announcements":"/engagements/seatgeek-vdp-pro/announcements","hallOfFame":"/engagements/seatgeek-vdp-pro/hall_of_fames","crowdstream":"/engagements/seatgeek-vdp-pro/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/seatgeek-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=seatgeek-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/seatgeek-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/seatgeek-vdp-pro/changelog","publishedAt":"2025-07-28T16:21:52.345Z","engagementChangelogUrl":"/engagements/seatgeek-vdp-pro/changelog/d490e919-ad94-4021-9936-c2606427777c","createUserFeedbacksUrl":"/engagements/seatgeek-vdp-pro/feedbacks","engagementCrowdstreamUrl":"/engagements/seatgeek-vdp-pro/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}