{"id":"136f05a0-10c7-428a-b65f-d9dfc27b662b","engagementId":"af631704-b8bd-4647-893a-0c12d00a1f05","data":{"brief":{"id":"c23c6a65-9c30-420b-9a11-d8396dbfd741","name":"Skroutz Public Managed Bug Bounty","tagline":"Skroutz","description":"\u003cp\u003eSkroutz S.A. is the prime Greek e-commerce and online marketplace platform. We are dedicated to offering our customers and partners top-quality services while maintaining a strong security posture; protecting our customer’s data \u0026amp; privacy is our highest priority. To that end we welcome contributions from security researchers as part of Bugcrowd’s private bug bounty program with the aim of identifying and mitigating any security flaws, gaps and vulnerabilities present in our platform.\u003c/p\u003e\n\n\u003cp\u003eSecurity researchers are invited to conduct extensive research on our live production environment (detailed below), to guarantee accuracy and relevance of reported findings. as long as the stability, integrity and availability of the production environment \u003cstrong\u003eis not severely affected by said research\u003c/strong\u003e.\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch3\u003eTesting Guidelines:\u003c/h3\u003e\n\n\u003cp\u003eWhile aiming to assist security researchers succeed in our bug bounty program, we expect all participants to adhere to some basic guidelines for interacting with and assessing our platform and supporting services as defined here:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eProvide clear details of any finding, including detailed steps to replicate, any applicable PoC, potential impact and mitigation recommendations\u003c/li\u003e\n\u003cli\u003eDo your absolute best to act in good faith, avoiding any potential destruction of data and services, excessive disruption of services and any privacy violations, reporting any concerns around these topics to the Skroutz team.\u003c/li\u003e\n\u003cli\u003eMake sure to comply with all relevant \u0026amp; applicable cybersecurity and privacy laws\u003c/li\u003e\n\u003cli\u003eBe patient when submitting findings for the Skroutz security team to review and accept as we need to prioritize tasks based on their severity and impact to our platform\u003c/li\u003e\n\u003cli\u003eContact the Skroutz team immediately when you detect any leakage of real customer data that would constitute a privacy breach\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch1\u003eAI Generated submissions\u003c/h1\u003e\n\n\u003cp\u003eAs we are seeing a growing number of submissions that appear to be generated primarily by AI reviews with reduced to no human verification before submission, we require the researchers to properly check all submissions. Recent reports have described intentional, by-design behaviors (e.g. promotional/voucher mechanisms deliberately not scoped to a single user or cart as Broken Access Control or IDOR) without verification.\u003c/p\u003e\n\n\u003cp\u003eMore precisely:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAll submissions must demonstrate actual, verified impact. Submissions such as \"this parameter is not scoped similarly with X endpoint\" will be marked at best as P5 - Informational or even penalized. The same applies for submissions that are mostly security suggestions or improvements. Design inconsistencies are not flaws without verifiable evidence.\u003c/li\u003e\n\u003cli\u003eDifferential responses are not a vulnerability without a replay-able attack scenario.\u003c/li\u003e\n\u003cli\u003eReports that read as AI-generated analysis without human verification, concrete exploitation scenario may be closed as Not Applicable/Not Reproducible.\u003c/li\u003e\n\u003cli\u003eMassive artifact logs without curation will be ignored or downgraded.\u003c/li\u003e\n\u003cli\u003eConsecutive submission spraying with P5 or Not Applicable or Not Reproducible findings may end up in banning a researcher from our program.\u003c/li\u003e\n\u003cli\u003eThe researchers are \u003cstrong\u003eALWAYS\u003c/strong\u003e accountable for each submission.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eAs tooling has evolved, and we do not wish to ban AI submissions, use whatever helps you but own it end-to-end. We are more than happy to engage on edge-cases or re-open cases upon new evidence, but high submission volume with low hit-rate cost us human triage time and it affects turnaround for everyone, including well-researched reports.\u003c/p\u003e\n\n\u003cp\u003eThank you for continuing to test us, so let's move the bar on verification upwards instead of degrading the quality of our program.\u003c/p\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Skroutz not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Skroutz, you can report it to this program. However, be aware that it is ineligible for points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eTarget Information:\u003c/h2\u003e\n\n\u003cp\u003eThe targets for this engagement are the Skroutz web application and its associated API on the live production environment. The application is built with Ruby on Rails and is a full scale e-commerce web application. The frontend is React. Many of the Skroutz components are built with Open Source Software, some of the components that they use are available at: \u003ca href=\"https://github.com/skroutz\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://github.com/skroutz\u003c/a\u003e.  The program will take place in a production environment with live data and must be treated with due care accordingly. Skroutz's main web application uses Greek as the primary language of the website, however we have launched alternative versions of the website with localised content for various European markets (including English), you are free to use any alternative language and/or website flavour. All website flavours serve the same backend code (so it is essentially a single bounty target), so you can test on any of the following flavors :\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003ca href=\"https://www.skroutz.gr/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eskroutz.gr\u003c/a\u003e - main\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.skroutz.de/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eskroutz.de\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.skroutz.bg/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eskroutz.bg\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.skroutz.ro/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eskroutz.ro\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.skroutz.cy/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eskroutz.cy\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.skroutz.eu/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eskroutz.eu\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eNote: These flavors are translations of the same main \u003ca href=\"https://www.skroutz.gr/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eskroutz.gr\u003c/a\u003e Skroutz web application.\u003c/p\u003e\n\n\u003cp\u003eThe following are true for the environment:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe web applications in scope are served through a HAProxy load-balancer setup that routes traffic to the relevant application servers (unicorn).\u003c/li\u003e\n\u003cli\u003eSecurity controls might be in place to block certain payloads or common attacks for the bounty environment (ex. WAF).\u003c/li\u003e\n\u003cli\u003eThe main web application can be accessed using its normal user registration flow. Researchers can create their own user accounts at will through the default registration process of the application. We strongly suggest that you \u003cstrong\u003ekeep new account registrations at a minimum\u003c/strong\u003e, as required to test effectively, as to not skew our business metrics and analytics\u003c/li\u003e\n\u003cli\u003eThe environment is configured to forward emails to all email addresses.\u003c/li\u003e\n\u003cli\u003ePayments cannot and should not be completed as we do not provide testing credit card numbers or similar functionality. \u003cstrong\u003eDO NOT attempt to complete purchases with your own credit cards or payment methods as we CANNOT guarantee any partial or full refunds.\u003c/strong\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eAPI Information and Documentation:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eFull production documentation available here: \u003ca href=\"https://developer.skroutz.gr/api/v3/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://developer.skroutz.gr/api/v3/\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eAuthentication \u0026amp; Authorization is managed by leveraging the OAuth2 protocol. It requires a client_id \u0026amp; client_secret to issue OAuth2 tokens to be used for all subsequent requests.\u003c/li\u003e\n\u003cli\u003eNo client_id \u0026amp; client_secret values are provided to normal production users, the API endpoints are included here for testing from an unauthenticated perspective. Of course you are free to attempt to bypass authentication/authorization of the API endpoints and access their functions without a provided client_id \u0026amp; client_secret.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess:\u003c/h2\u003e\n\n\u003cp\u003eThe target web application is our live environment and is, therefore, readily accessible through the Internet.\u003c/p\u003e\n\n\u003ch3\u003eCredentials:\u003c/h3\u003e\n\n\u003cp\u003eAs mentioned you can register user accounts to access the main Skroutz application through the normal registration flow. As this bounty program's scope aims to be identical to that of a standard user level attacker, we do not provide any pre-provisioned accounts with additional access rights or other roles. \u003c/p\u003e\n\n\u003cp\u003eAlways keep in mind that this is a live production environment so you should **keep user account registrations,  at a minimum and you should protect your accounts as you normally would in any other web application. Do not share your credentials with other researchers as you are ultimately responsible for the privacy and security of your account.\u003c/p\u003e\n\n\u003ch2\u003eFocus Areas:\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthentication process\u003c/li\u003e\n\u003cli\u003eAPI endpoints and their functions\u003c/li\u003e\n\u003cli\u003eCheckout/Payment step workflows - Steps involving credit card details - WITHOUT completing payments\u003c/li\u003e\n\u003cli\u003eSmart Basket Functionality (\"Purchase from Skroutz\")\n\n\u003cul\u003e\n\u003cli\u003ePurchase directly through our website\u003c/li\u003e\n\u003cli\u003eIncluding merchants without a website\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eSkroutz Gift Cards (treated as a normal product at checkout but can then be used as coupons on subsequent order). Abusing the Gift Card behaviour would be an important risk to look for. (Assuming you have staging access via Bugcrowd whitelisted IPs you can see the products here : https://www.bounty.skroutz.dev/c/4802/dorokartes.html?o=gift+cards)\u003c/li\u003e\n\u003cli\u003eEmail Verification Sign-Up : We recently introduced mandatory email verification for all new signups with normal Skroutz username/password accounts. We are interested to see if we covered all bases in terms of security\u003c/li\u003e\n\u003cli\u003eSkroutz Plus + Friend Referals : Skroutz Plus is our loyalty subscription program and we’ve recently introduced a referral bonus scheme on it and we would like for it to be tested for potential abuse or other security flaws (https://www.bounty.skroutz.dev/account/plus - Requires being logged in first with one of the provided accounts)\u003c/li\u003e\n\u003cli\u003eSkroutz Skoop, our consumer-to-consumer marketplace where you can sell your items and buy other users' items leveraging Skroutz's efficient user journey. We are particularly interested in security vulnerabilities as well as abuses that can bypass our buyer protection guarantees\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut-of-Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eOur AI-chatbot agent\u003c/li\u003e\n\u003cli\u003eD/DoS\u003c/li\u003e\n\u003cli\u003eCross-Site Request Forgery (CSRF) issues (Currently aware of all relevant issues)\u003c/li\u003e\n\u003cli\u003eHTTP security headers (Unless they lead to a demonstrable impact on user data/sensitive functions)\u003c/li\u003e\n\u003cli\u003eBrowser cookie security flags (Unless they lead to a demonstrable impact on user data/sensitive functions)\u003c/li\u003e\n\u003cli\u003eSSL/TLS related issues (ex. Weak ciphers, certificate strength etc.)\u003c/li\u003e\n\u003cli\u003ePassword policy (ex. Low password complexity, expiration, password reset timeout etc.)\u003c/li\u003e\n\u003cli\u003eSession expiration time interval\u003c/li\u003e\n\u003cli\u003eSelf-XSS\u003c/li\u003e\n\u003cli\u003eError messages - Unless they lead to customer private data exposure\u003c/li\u003e\n\u003cli\u003eClickjacking issues\u003c/li\u003e\n\u003cli\u003eAccount lockout policies\u003c/li\u003e\n\u003cli\u003eAbsence of security controls (ex. Rate-limiting or WAF)\u003c/li\u003e\n\u003cli\u003eVulnerability only relevant to users of legacy/obsolete/out-of-date browsers\u003c/li\u003e\n\u003cli\u003eEmail server issues - Unless directly exploitable through the web application/API targets\u003c/li\u003e\n\u003cli\u003eEmail/Username enumeration (other enumerations are in scope)\u003c/li\u003e\n\u003cli\u003eOut-of-date vulnerable third-party libraries (Unless you can demonstrate exploitability of the vulnerability on the web application)\u003c/li\u003e\n\u003cli\u003ePassword Leaks/Dumps on credentials from third-party websites (e.g. Dehashed)\u003c/li\u003e\n\u003cli\u003eSocial Engineering - Unless they lead to a feasible and easily reproducible scenario\u003c/li\u003e\n\u003cli\u003eValidation issues on Skroutz Skoop (ex. no validation on address, tax code, mobile number, KYC etc - these are on purpose)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003e2FA\u003c/h2\u003e\n\n\u003cp\u003eWe are currently developing a 2FA mechanism so it is of utmost importance if a bypass or vulnerability is found.\u003cbr\u003e\nNote for the 2FA: The mechanism is not implemented everywhere, but only in specific endpoints / actions.\u003cbr\u003e\nExamples:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNot enabled for login.\u003c/li\u003e\n\u003cli\u003eEnabled when changing email address from the user page.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eForbidden Activities\u003c/h2\u003e\n\n\u003cp\u003eThe following activities are strictly prohibited, will not be eligible for any rewards and may even result in researcher accounts/IP addresses/clients getting banned from the production environment altogether: \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDenial of Service \u0026amp; Distributed Denial of Service attacks. \u003cstrong\u003eDo not attempt to interrupt the production environment's stability/availability\u003c/strong\u003e. If you discover a relevant issue please cease all testing and report it to the program directly for triage.\u003c/li\u003e\n\u003cli\u003eIP/port scanning\u003c/li\u003e\n\u003cli\u003eAttacking the load-balancers that serve the applications and API endpoints directly\u003c/li\u003e\n\u003cli\u003eAttacking the network and/or hosts of the applications and API endpoints directly - unless possible through an application/API vulnerability\u003c/li\u003e\n\u003cli\u003eExcessive aggression on automated scanning tools : always pace your scanning tools to a reasonable amount of concurrent requests against the environment\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eDo not create huge amounts of new database entries via automated means\u003c/strong\u003e (ex. New accounts) - Only create what is necessary for your testing in a manual or semi-automated manner\u003c/li\u003e\n\u003cli\u003eDo not attempt to brute force any credentials of any kind\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"e3fe86dd-586a-4031-93a9-a64f99986bd3","name":"Skroutz Public Application","targets":[{"id":"76f97852-306d-42e9-8bbc-328498aacaa6","uri":"https://www.skroutz.gr","name":"https://www.skroutz.gr","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"448eb330-7b53-439a-be95-4785cfac767e","sortOrder":0},"sortOrder":0,"tags":[{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"76f97852-306d-42e9-8bbc-328498aacaa6"},{"id":"4e9d5c53-3b04-4bca-ba30-e8e33d87019a","name":"Ruby on Rails","targetId":"76f97852-306d-42e9-8bbc-328498aacaa6"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"76f97852-306d-42e9-8bbc-328498aacaa6"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"775f4cdf-c618-4ddf-8e9d-66ac55ab901f","p1MaxCents":500000,"p1MinCents":400000,"p2MaxCents":200000,"p2MinCents":100000,"p3MaxCents":90000,"p3MinCents":50000,"p4MaxCents":30000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003cp\u003eYou are testing directly on Skroutz\u0026#39;s production environment. Behavior that compromises the stability and integrity of the site is strictly forbidden \u0026amp; out of scope. For example, do not target other user\u0026#39;s data (use one of your other sets of credentials), delete/remove/edit parts of the site, engage any sort of DoS attack, and/or compromise any target\u0026#39;s ability to function for other users. If you believe that you have found a vulnerability of this nature, please cease all further testing and report it immediately.\u003c/p\u003e","rewardRangeData":{"1":{"min":4000,"max":5000},"2":{"min":1000,"max":2000},"3":{"min":500,"max":900},"4":{"min":100,"max":300},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"af631704-b8bd-4647-893a-0c12d00a1f05","code":"skroutz","state":"in_progress","endsAt":null,"bountyId":"4cce5f78-5814-4070-9269-adf5cac4855e","startsAt":"2022-01-11T05:30:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/eedc/7027/5e167a91/da511d3b0ab66f96649676e4a2ee0961_1624451643286.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2022-01-11T05:30:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/skroutz","changelogs":"/engagements/skroutz/changelog","submissions":null,"announcements":"/engagements/skroutz/announcements","hallOfFame":"/engagements/skroutz/hall_of_fames","crowdstream":"/engagements/skroutz/crowdstream"},"announcementsCount":5,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/skroutz/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=skroutz\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/skroutz/engagement_subscribers","engagementChangelogsUrl":"/engagements/skroutz/changelog","publishedAt":"2026-08-19T08:55:17.524Z","engagementChangelogUrl":"/engagements/skroutz/changelog/136f05a0-10c7-428a-b65f-d9dfc27b662b","createUserFeedbacksUrl":"/engagements/skroutz/feedbacks","engagementCrowdstreamUrl":"/engagements/skroutz/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}