{"id":"2c1e110f-7462-40b2-9539-13e36cd1dd1d","engagementId":"eb6c41e5-20d5-4fcc-8927-25f3ebcf6c0c","data":{"brief":{"id":"0d4896dc-584e-4b8e-b1de-2e9ac2a28195","name":"Skyscanner","tagline":"We’re the travel company who puts you first. All the flight, hotel and car hire options you need, all in one place.  We are offering $100 - $8000 per vulnerability.","description":"\u003ch1\u003eWelcome to Skyscanner's Bug Bounty program\u003c/h1\u003e\n\n\u003cp\u003eKeeping traveller's information safe and secure is a top priority for Skyscanner. We welcome the contribution of security researchers and look forward to rewarding them for their invaluable contribution to the security of all Skyscanner travellers.\u003c/p\u003e\n\n\u003cp\u003eWe invite researchers to test the Skyscanner website and mobile apps in line with the principles set out in this brief.\u003c/p\u003e\n\n\u003ch2\u003eGuidelines\u003c/h2\u003e\n\n\u003cp\u003eWe request thorough proof-of-concept/replication of the bug, including videos, images, and a description of the business impact. These will all factor into our bounty decision-making process.\u003c/p\u003e\n\n\u003cp\u003eTo promote the discovery and reporting of vulnerabilities we ask that you:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eshare the security issue with us in detail\u003c/li\u003e\n\u003cli\u003eact in good faith to avoid privacy violations, destruction of data, and interruption or degradation of our services (including Denial of Service)\u003c/li\u003e\n\u003cli\u003ecomply with all applicable laws\u003c/li\u003e\n\u003cli\u003eunderstand that all valid reports will be taken seriously by our engineering teams\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eExpectations\u003c/h2\u003e\n\n\u003cp\u003eWe expect researchers to follow the program rules:\u003c/p\u003e\n\n\u003cp\u003eResearchers \u003cstrong\u003emust\u003c/strong\u003e:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eadd the following header to all HTTP requests: \u003ccode\u003eSkyscanner-Security: Bugcrowd\u003c/code\u003e\n\u003c/li\u003e\n\u003cli\u003euse your \u003ccode\u003eusername@bugcrowdninja.com\u003c/code\u003e email address for accounts\u003c/li\u003e\n\u003cli\u003enot access or modify our, or travellers' data, without explicit prior permission of the owner. Only interact with your own accounts or provided test accounts for security research purposes\u003c/li\u003e\n\u003cli\u003econtact us immediately if you inadvertently encounter traveller data. Do not view, alter, save, store, transfer, or otherwise access the data, and immediately purge any local information upon reporting the vulnerability to Skyscanner\u003c/li\u003e\n\u003cli\u003eperform testing and research only within the areas that are in scope\u003c/li\u003e\n\u003cli\u003efollow the \u003ca href=\"https://researcherdocs.bugcrowd.com/docs/disclosure\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Coordinated Disclosure rules\u003c/a\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eIn addition, we count the following activities as \u003cstrong\u003estrictly prohibited\u003c/strong\u003e, and thus not rewardable. These are in addition to the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eSocial Engineering attacks\u003c/li\u003e\n\u003cli\u003eDDoS\u003c/li\u003e\n\u003cli\u003eExcessive use of automated vulnerability / scanning tools\n\n\u003cul\u003e\n\u003cli\u003ePlease do not spam forms or account creation flows using automated scanners\u003c/li\u003e\n\u003cli\u003eWe have a number of rate limits in place that may result in your IP address being blocked if you use such tools\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eAny testing of corporate email (\u003ccode\u003e*@skyscanner.net\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eWe will offer monetary rewards for the \u003cstrong\u003efirst submitted report of a vulnerability\u003c/strong\u003e.\u003c/p\u003e\n\n\u003cp\u003ePublic disclosure of the vulnerability prior to resolution may cancel a pending reward. We reserve the right to disqualify individuals from the program for disrespectful or disruptive behaviour.\u003c/p\u003e\n\n\u003cp\u003eWe will not negotiate in response to duress or threats (e.g. we will not negotiate the payout amount under threat of withholding the vulnerability, or of releasing the vulnerability or any exposed data to the public).\u003c/p\u003e\n\n\u003cp\u003eWe reserve the right to \u003cstrong\u003ededuct a 10% penalty\u003c/strong\u003e on valid and accepted submissions that do not follow the guidelines mentioned above. Following the guidelines will help us triage the vulnerability more effectively from our side, which should result in faster processing of the submission\u003c/p\u003e\n\n\u003cp\u003eWe are under no obligation to pay out for any bugs that are not submitted in accordance with this policy or any of the Bugcrowd policies.\u003c/p\u003e\n\n\u003cp\u003eWe reserve the right to withdraw this scheme at any time and shall have no obligation to pay out for any bugs submitted after closure of the scheme.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch1\u003eRating \u0026amp; Reward Information:\u003c/h1\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program uses the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, please note that in some cases, the priority rating will be altered due to reflect the likelihood or impact of an exploit. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eWe will award greater bounties for all valid submissions contained in our Focus Areas (see Target Information).\u003c/strong\u003e\u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003ePriority\u003c/th\u003e\n\u003cth\u003eReward range\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003eP1\u003c/td\u003e\n\u003ctd\u003e$3,000 – $8,000*\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP2\u003c/td\u003e\n\u003ctd\u003e$900 – $3,000*\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP3\u003c/td\u003e\n\u003ctd\u003e$300 – $500\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003eP4\u003c/td\u003e\n\u003ctd\u003e$100 – $150\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003cp\u003e*The highest rewards will be reserved for submissions deemed to have high business criticality.\u003c/p\u003e\n\n\u003ch3\u003eOther:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities found in multiple fields in the same form or using the same CSRF token will be counted as a single vulnerability. Subsequent submissions will be marked as \u003ccode\u003eNot Applicable\u003c/code\u003e. Please detail all affected fields in a single submission.\u003c/li\u003e\n\u003cli\u003eVulnerabilities that can be exploited with similar payloads on the same path are only eligible for a single reward. Subsequent submissions will be marked \u003ccode\u003eNot Applicable\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eVulnerabilities exploitable with similar payloads on the same path/source will only be eligible for one reward, and additional reports will be marked \u003ccode\u003eNot Applicable\u003c/code\u003e. This approach ensures a focused and effective evaluation of distinct security risks.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eDNS Takeovers and Reward Adjustments:\u003c/h4\u003e\n\n\u003cp\u003eFor DNS takeovers involving main domains, the original reward amount will be maintained to reflect the severity and impact of the issue. However, for DNS takeovers associated with domains used primarily for brand protection, acknowledging their lower criticality, the reward amount will be decided post evaluation. If multiple reports are submitted for vulnerabilities with the same root cause, the initial submission will receive the full reward value, while subsequent reports will be marked \u003ccode\u003eNot Applicable\u003c/code\u003e.\u003c/p\u003e\n\n\u003ch4\u003eReporting leaked credentials:\u003c/h4\u003e\n\n\u003cp\u003eSubmissions about leaked credentials belonging to either systems/services in the scope or Skyscanner employees, will be rewarded \u003cstrong\u003eonly\u003c/strong\u003e with program points and \u003cstrong\u003enot\u003c/strong\u003e with a bounty reward.\u003c/p\u003e\n\n\u003ch2\u003e\n\u003ca href=\"https://disclose.io/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eSafe Harbor\u003c/a\u003e compliance\u003c/h2\u003e\n\n\u003cp\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eYou are expected, as always, to comply with all applicable laws.\u003c/p\u003e\n\n\u003cp\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through one of our Official Channels before going any further.\u003c/p\u003e","industryTagId":"948573e8-bbbb-4552-918a-f87250ebe1fc","targetsOverview":"\u003ch1\u003eTarget info:\u003c/h1\u003e\n\n\u003cp\u003eBelow is a summary of all the targets we will consider submissions for. Please read this section thoroughly for more information on each target, as well as our main Focus Areas.\u003c/p\u003e\n\n\u003ch2\u003eSkyscanner website\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003ehttps://*.skyscanner.net/*\u003c/code\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities found in any other regional domain with the same codebase (such as \u003ccode\u003eskyscanner.fr/*\u003c/code\u003e) will be considered the same vulnerability\u003c/li\u003e\n\u003cli\u003eAll subdomains are in the scope of this program unless explicitly excluded\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eSkyscanner iOS and Android Apps\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eSkyscanner iOS App can be downloaded from the \u003ca href=\"https://itunes.apple.com/us/app/skyscanner/id415458524?mt=8\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eApple App Store\u003c/a\u003e\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSkyscanner Android App can be downloaded from the \u003ca href=\"https://play.google.com/store/apps/details?id=net.skyscanner.android.main\u0026amp;hl=en_GB\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eGoogle Play Store\u003c/a\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eApplication code in the APK and any data it creates and saves on the device\u003c/li\u003e\n\u003cli\u003eFeatures or code provided by separate web services will be in the scope of the \u003cstrong\u003eservice itself\u003c/strong\u003e, not the app\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch1\u003eFocus Areas\u003c/h1\u003e\n\n\u003ch2\u003eskyscanner.net/profile/*\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eAuth0 endpoints should be used only to:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eTest authentication and session management flows\u003c/li\u003e\n\u003cli\u003eManually verify potential vulnerabilities like XSS / Open Redirects\u003c/li\u003e\n\u003cli\u003eHandling stored payment details (Card Tokens)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cp\u003e\u003cstrong\u003eImportant:\u003c/strong\u003e See the \u003ccode\u003eOut of Scope\u003c/code\u003e section (below) for issues not in scope\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eRe-owning Anonymous Bookings by fully verified account using Mobile Applications.\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eImplementation of the Anonymous Bookings Re-owning feature to allow travellers to re-own anonymous bookings which they did whilst unauthenticated. This flow relies on the bookings made using the same email address using the mobile application (Deeplink with BookingHistory and BookingDetails endpoints). \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eThis feature uses  the \"Secure-anon_token\" cookie, account verification state and matching traveller details to one submitted during the booking\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003epartnerportal.skyscanner.net/*\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003e\u003cstrong\u003ePlease note that a user account will not be provided\u003c/strong\u003e\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eWe are interested in testing for:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthentication issues\u003c/li\u003e\n\u003cli\u003eSerious information disclosure\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch1\u003eOut of Scope\u003c/h1\u003e\n\n\u003cp\u003eThe following issues are outside the scope of our rewards program:\u003c/p\u003e\n\n\u003ch4\u003eThird Party tools and services:\u003c/h4\u003e\n\n\u003cp\u003eVulnerabilities found in \u003cstrong\u003ethird party products or services\u003c/strong\u003e are not rewardable unless they are \u003cstrong\u003eunique to our configuration or present a serious business risk\u003c/strong\u003e (at our discretion).\u003c/p\u003e\n\n\u003cp\u003eThe following sub-domains are out of scope as they are hosted and managed by third parties: help.skyscanner.net, carhirehelp.skyscanner.net, hotelshelp.skyscanner.net, support.business.skyscanner.net, www.partners.skyscanner.net, creators.skyscanner.net, preferences.skyscanner.net\u003c/p\u003e\n\n\u003ch4\u003eOut-of-scope on \u003ccode\u003eskyscanner.net/profile/*\u003c/code\u003e:\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003ePassword, email and account policies, such as email id verification, reset link expiration, password complexity, session expiry\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eAny report that relates to learning whether a given username, email address has a Skyscanner account.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eAbility to share links without verifying email.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eLarge scale account enumeration or brute force that might lead the lock-out of a real user's account\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eAuth0 endpoints\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch4\u003eOther:\u003c/h4\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003cp\u003eAttacks requiring physical access to a user's device.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eHost header injections unless you can show how they can lead to stealing user data.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eReports of spam (i.e., any report involving the ability to send emails without rate limits).\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eAttacks that require the attacker app to have permission to overlay on top of our app (e.g., tapjacking).\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eVulnerabilities affecting users of outdated browsers or platforms.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDMARC policies being set to \u003ccode\u003enone\u003c/code\u003e or SPF policies set to \u003ccode\u003eSoftFail\u003c/code\u003e.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eSocial engineering of Skyscanner employees or contractors.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eAny physical attempts against Skyscanner property or data centers.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eAny access to data where the targeted user needs to be operating a rooted mobile device.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eContent spoofing vulnerabilities (where you can only inject text or an image into a page) are out of scope. We will accept and resolve a spoofing vulnerability where attacker can inject image or rich text (HTML), but it is not eligible for a bounty. Pure text injection is out of scope.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eAbsence of rate limiting, unless related to authentication.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eIP/Port Scanning via Skyscanner services unless you are able to hit private IPs or Skyscanner servers.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eDevices (iOS, Android, desktop apps) not getting unlinked on password change.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003ePhishing risk via unicode/punycode or RTLO issues.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eCSRF-based modification of currency, locale, and market parameters.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"1fabe0e0-cde4-4608-aaee-d4379fe9d2ab","name":"In scope targets","targets":[{"id":"f24206ea-d82b-4521-b8ee-0520d39b4b2b","uri":null,"name":"Skyscanner iOS App","category":"ios","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"48cbacb2-3abf-4ca4-b4a6-79221938500e","sortOrder":0},"sortOrder":0,"tags":[{"id":"63c4a71d-215f-49ca-8ea8-240dfbf82d61","name":"Objective-C","targetId":"f24206ea-d82b-4521-b8ee-0520d39b4b2b"},{"id":"7692155d-e2db-4c50-abd5-208448a85fde","name":"SwiftUI","targetId":"f24206ea-d82b-4521-b8ee-0520d39b4b2b"},{"id":"a47bcaa8-a080-4539-b4ca-e699e72d2023","name":"Swift","targetId":"f24206ea-d82b-4521-b8ee-0520d39b4b2b"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"f24206ea-d82b-4521-b8ee-0520d39b4b2b"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"f24206ea-d82b-4521-b8ee-0520d39b4b2b"}],"recentChangeFlags":null},{"id":"bf901882-af8c-4b6a-b2d7-37eb9ab80294","uri":null,"name":"Skyscanner Android App","category":"android","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"d69a6713-ce43-4c6b-9177-a96235f822af","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"bf901882-af8c-4b6a-b2d7-37eb9ab80294"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"bf901882-af8c-4b6a-b2d7-37eb9ab80294"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"bf901882-af8c-4b6a-b2d7-37eb9ab80294"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"bf901882-af8c-4b6a-b2d7-37eb9ab80294"}],"recentChangeFlags":null},{"id":"f1cb2ffa-db08-4104-963f-6b43077e31e2","uri":null,"name":"gateway.skyscanner.net/*","category":"api","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"935e4601-ce8b-4e8c-a4f4-907c5a792edb","sortOrder":0},"sortOrder":0,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"f1cb2ffa-db08-4104-963f-6b43077e31e2"},{"id":"cbf0ee58-c41b-4dee-9d08-cefd01f5d7d6","name":"HTTP","targetId":"f1cb2ffa-db08-4104-963f-6b43077e31e2"}],"recentChangeFlags":null},{"id":"da49ac23-1ea3-4269-bbc3-1b4fe69a693d","uri":null,"name":"skyscanner.net/hotels/book/*","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"baef7355-2562-4e47-a1a5-fdda6aadc139","sortOrder":0},"sortOrder":0,"tags":[{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"da49ac23-1ea3-4269-bbc3-1b4fe69a693d"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"da49ac23-1ea3-4269-bbc3-1b4fe69a693d"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"da49ac23-1ea3-4269-bbc3-1b4fe69a693d"},{"id":"a5bf7fc5-03c4-42f4-b10d-5ceb23d1c064","name":"Lodash","targetId":"da49ac23-1ea3-4269-bbc3-1b4fe69a693d"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"da49ac23-1ea3-4269-bbc3-1b4fe69a693d"}],"recentChangeFlags":null},{"id":"c12e59a1-ff33-4e5a-9c00-ce90018dd290","uri":null,"name":"skyscanner.net/*","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"ca8fe525-4e09-4dd7-bd3b-b5d5c579970a","sortOrder":0},"sortOrder":0,"tags":[{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"c12e59a1-ff33-4e5a-9c00-ce90018dd290"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"c12e59a1-ff33-4e5a-9c00-ce90018dd290"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"c12e59a1-ff33-4e5a-9c00-ce90018dd290"},{"id":"a5bf7fc5-03c4-42f4-b10d-5ceb23d1c064","name":"Lodash","targetId":"c12e59a1-ff33-4e5a-9c00-ce90018dd290"},{"id":"b556fc49-2c15-4167-b815-c89ac5d8a974","name":"Lua","targetId":"c12e59a1-ff33-4e5a-9c00-ce90018dd290"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"c12e59a1-ff33-4e5a-9c00-ce90018dd290"}],"recentChangeFlags":null},{"id":"4b12d6b3-2c0f-48c9-b316-2a014b2c2ddb","uri":null,"name":"partnerportal.skyscanner.net/*","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"69257cb2-63ee-42ca-878a-7f2fa9c86bf6","sortOrder":0},"sortOrder":0,"tags":[{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"4b12d6b3-2c0f-48c9-b316-2a014b2c2ddb"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"4b12d6b3-2c0f-48c9-b316-2a014b2c2ddb"},{"id":"d2e9f7fd-1403-4a01-b5b8-fba5e0f49e37","name":"ExpressJS","targetId":"4b12d6b3-2c0f-48c9-b316-2a014b2c2ddb"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"4b12d6b3-2c0f-48c9-b316-2a014b2c2ddb"}],"recentChangeFlags":null},{"id":"0f0d6bcb-a945-4e1d-9238-4b7c0dfeeea1","uri":null,"name":"*.skyscanner.net","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e7dd62ae-2336-4489-878e-9385db2a4c9b","sortOrder":0},"sortOrder":0,"tags":[{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"0f0d6bcb-a945-4e1d-9238-4b7c0dfeeea1"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"0f0d6bcb-a945-4e1d-9238-4b7c0dfeeea1"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"0f0d6bcb-a945-4e1d-9238-4b7c0dfeeea1"},{"id":"a5bf7fc5-03c4-42f4-b10d-5ceb23d1c064","name":"Lodash","targetId":"0f0d6bcb-a945-4e1d-9238-4b7c0dfeeea1"},{"id":"b556fc49-2c15-4167-b815-c89ac5d8a974","name":"Lua","targetId":"0f0d6bcb-a945-4e1d-9238-4b7c0dfeeea1"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"0f0d6bcb-a945-4e1d-9238-4b7c0dfeeea1"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"bafe3e9e-2f91-4295-986b-81d650e36bbd","p1MaxCents":800000,"p1MinCents":300000,"p2MaxCents":300000,"p2MinCents":90000,"p3MaxCents":50000,"p3MinCents":30000,"p4MaxCents":15000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":3000,"max":8000},"2":{"min":900,"max":3000},"3":{"min":300,"max":500},"4":{"min":100,"max":150},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"1ad306d8-a1a3-42b4-904a-48a71cb79850","name":"AI Bias Testing","targets":[{"id":"2e074035-ec94-4a57-93d3-9de419b7e282","uri":null,"name":"Skyscanner Android app","category":"android","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e00c23e0-498f-4871-a874-79b2a638e74c","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"2e074035-ec94-4a57-93d3-9de419b7e282"},{"id":"785c5b22-9fbd-4f54-83f0-336e4e417b17","name":"Large Language Model","targetId":"2e074035-ec94-4a57-93d3-9de419b7e282"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"2e074035-ec94-4a57-93d3-9de419b7e282"},{"id":"b120236f-99c4-4a51-8285-8e5cc782ff27","name":"AI Bias Testing","targetId":"2e074035-ec94-4a57-93d3-9de419b7e282"},{"id":"c4d77d88-21a3-4a8d-81b7-555e301c483e","name":"Kotlin","targetId":"2e074035-ec94-4a57-93d3-9de419b7e282"},{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"2e074035-ec94-4a57-93d3-9de419b7e282"}],"recentChangeFlags":null},{"id":"afdd8a28-9ed8-4785-bd8b-bd193b42ab78","uri":null,"name":"Skyscanner iOS app","category":"ios","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"228b2142-a49b-47c1-8e2a-ec46159613cb","sortOrder":0},"sortOrder":0,"tags":[{"id":"63c4a71d-215f-49ca-8ea8-240dfbf82d61","name":"Objective-C","targetId":"afdd8a28-9ed8-4785-bd8b-bd193b42ab78"},{"id":"7692155d-e2db-4c50-abd5-208448a85fde","name":"SwiftUI","targetId":"afdd8a28-9ed8-4785-bd8b-bd193b42ab78"},{"id":"785c5b22-9fbd-4f54-83f0-336e4e417b17","name":"Large Language Model","targetId":"afdd8a28-9ed8-4785-bd8b-bd193b42ab78"},{"id":"a47bcaa8-a080-4539-b4ca-e699e72d2023","name":"Swift","targetId":"afdd8a28-9ed8-4785-bd8b-bd193b42ab78"},{"id":"a6a12b60-e857-44a3-9cc9-3aa9a21aa203","name":"Mobile Application Testing","targetId":"afdd8a28-9ed8-4785-bd8b-bd193b42ab78"},{"id":"b120236f-99c4-4a51-8285-8e5cc782ff27","name":"AI Bias Testing","targetId":"afdd8a28-9ed8-4785-bd8b-bd193b42ab78"},{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"afdd8a28-9ed8-4785-bd8b-bd193b42ab78"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":1,"description":null,"rewardRange":{"id":"155da4c5-8617-47aa-897f-42effbe9d290","p1MaxCents":400000,"p1MinCents":300000,"p2MaxCents":250000,"p2MinCents":90000,"p3MaxCents":50000,"p3MinCents":30000,"p4MaxCents":15000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eOverview\u003c/h2\u003e\n\n\u003cp\u003eOur mobile application offers a unique feature for travelers to receive recommendations and destinations based on their specific queries. This functionality is powered by an instance of OpenAI, which processes user requests and provides appropriate location suggestions. The recommendations are limited to locations where we operate and are only available to users in English-speaking markets.\u003c/p\u003e\n\n\u003ch3\u003eFunctionality Description\u003c/h3\u003e\n\n\u003col\u003e\n\u003cli\u003e\u003cp\u003eUser Query Submission: Users can submit queries asking for travel recommendations.\u003cbr\u003e\nExample Query: \u0026quot;I would like to make a gastronomic travel.\u0026quot;\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eResponse Generation: The OpenAI instance processes the query and responds with a list of valid destinations.\u003cbr\u003e\nExample Output:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eParis\u003c/li\u003e\n\u003cli\u003eTokyo\u003c/li\u003e\n\u003cli\u003eRome\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eMarket Limitation: \u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eThis feature is only accessible in English-speaking markets.\u003c/li\u003e\n\u003cli\u003eRecommendations are restricted to locations where our services are available.\u003c/li\u003e\n\u003c/ul\u003e\u003c/li\u003e\n\u003c/ol\u003e\n\n\u003ch3\u003eScope of Testing\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eVerify that the functionality accurately processes user queries and returns only appropriate recommendations (no harmful, offensive, or deceptive content are allowed).\u003c/li\u003e\n\u003cli\u003eThe AI/Savvy search has been trained with publicly available past data, making new information not available in the model, so it may display inexact or outdated information sometimes. That is an acceptable behavior from LLM models.\u003c/li\u003e\n\u003cli\u003eVerify that is not possible to perform attacks like prompt injection, data poisoning, etc.\u003c/li\u003e\n\u003cli\u003eOnly safety/security issues will be accepted. Ambiguous or unspecific responses from the AI are expected.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eExclusions\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eInternal information is not shared via this feature; therefore, the risk of data leakage is very low.\u003c/li\u003e\n\u003cli\u003eTesting should focus on having appropriate and valid recommendations, rather than backend vulnerabilities.\u003c/li\u003e\n\u003cli\u003eAny other feature of the mobile application is out of the scope. \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eReporting Guidelines\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eClearly describe the steps to reproduce any issues found, and the impact it would have.\u003c/li\u003e\n\u003cli\u003eProvide screenshots or recordings where possible to illustrate the issue.\u003c/li\u003e\n\u003cli\u003eEnsure that any reported issues are within the scope of the described functionality.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eReward Criteria\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eValid issues related to unlawful recommendations or access limitations will be considered for rewards.\u003c/li\u003e\n\u003cli\u003eOut-of-scope issues, such as backend vulnerabilities unrelated to the described functionality, will not be eligible for rewards.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eExample Query for Testing\u003c/h3\u003e\n\n\u003cp\u003eQuery: \u0026quot;_I would like to explore historical sites. _\u0026quot;\u003cbr\u003e\nExpected Output: (Example)\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAthens\u003c/li\u003e\n\u003cli\u003eCairo\u003c/li\u003e\n\u003cli\u003eBeijing\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eBy following these instructions, you can effectively test the travel recommendation functionality in our mobile application and contribute to improving its accuracy and reliability.\u003c/p\u003e\n\n\u003cp\u003e\u003cimg src=\"https://bugcrowd.com/engagements/skyscanner/attachments/8a12c35b-dba5-467c-a82d-58640aa51261\" alt=\"image001.jpg\"\u003e\u003cbr\u003e\n\u003cimg src=\"https://bugcrowd.com/engagements/skyscanner/attachments/8cea2284-3a27-47fd-a65c-2ac042f2da14\" alt=\"image002.jpg\"\u003e\u003cbr\u003e\n\u003cimg src=\"https://bugcrowd.com/engagements/skyscanner/attachments/f2464603-a480-4f00-ae85-afe81d880ef2\" alt=\"image003.jpg\"\u003e\u003cbr\u003e\n\u003cimg src=\"https://bugcrowd.com/engagements/skyscanner/attachments/e666881d-9bb6-4582-a4c7-4f3a6866450c\" alt=\"image004.jpg\"\u003e\u003cbr\u003e\n\u003cimg src=\"https://bugcrowd.com/engagements/skyscanner/attachments/7395e87a-20cf-41d3-b2ec-afc58138cda1\" alt=\"image005.jpg\"\u003e\u003cbr\u003e\n\u003cimg src=\"https://bugcrowd.com/engagements/skyscanner/attachments/94c805db-df0b-4fe6-abf1-3f9edf1beaa5\" alt=\"image006.jpg\"\u003e\u003cbr\u003e\n\u003cimg src=\"https://bugcrowd.com/engagements/skyscanner/attachments/04cc2962-cff1-427b-bbf6-06b61f06f136\" alt=\"image007.jpg\"\u003e\u003c/p\u003e","rewardRangeData":{"1":{"min":3000,"max":4000},"2":{"min":900,"max":2500},"3":{"min":300,"max":500},"4":{"min":100,"max":150},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"f0464f3f-772c-4d53-af84-ba2d523acfe5","name":"AWS Infrastructure","targets":[{"id":"a9e987c1-1dbf-4ce6-bc57-44cacff68083","uri":"","name":"AWS Infrastructure","category":"other","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b11d7707-0b5c-49d9-b9be-64604c55b034","sortOrder":0},"sortOrder":0,"tags":[{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"a9e987c1-1dbf-4ce6-bc57-44cacff68083"},{"id":"803518dc-5ae1-4e48-8de4-5b61b42a6bd0","name":"Amazon S3","targetId":"a9e987c1-1dbf-4ce6-bc57-44cacff68083"},{"id":"9dd4899d-3a63-4126-8c83-c1fc1de50c25","name":"Amazon Cloudfront","targetId":"a9e987c1-1dbf-4ce6-bc57-44cacff68083"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":2,"description":null,"rewardRange":{"id":"155da4c5-8617-47aa-897f-42effbe9d290","p1MaxCents":400000,"p1MinCents":300000,"p2MaxCents":250000,"p2MinCents":90000,"p3MaxCents":50000,"p3MinCents":30000,"p4MaxCents":15000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eOverview\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWe accept AWS infrastructure related submissions for the configuration of services such as Route53, S3, or Cloudfront; as long as they are clearly related to Skyscanner\u0026#39;s resources in the AWS cloud.\u003c/li\u003e\n\u003cli\u003eExample of these issues are Route 53 dangling records, unprotected S3 buckets, or insecure Cloudfront distribution configuration.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eScope\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eYou must comply with \u003ca href=\"https://aws.amazon.com/security/penetration-testing/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eAWS Customer Service Policy for Security Testing\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eThe issue should be related to a Skyscanner\u0026#39;s specific configuration (We will not accept vulnerabilities in services with a default configuration or general AWS issues).\u003c/li\u003e\n\u003cli\u003eYou must provide a proof of concept for the issue (Theoretic issues such as \u0026quot;weak encryption\u0026quot; will not be accepted without a demonstration).\u003c/li\u003e\n\u003cli\u003eThe output of automated tools alone will not be accepted as proof of concept / impact.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eReward Criteria\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eThe issues would be rewarded according to the impact on Skyscanner\u0026#39;s services alone, and not on other third parties.\u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":3000,"max":4000},"2":{"min":900,"max":2500},"3":{"min":300,"max":500},"4":{"min":100,"max":150},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"b28b1c3f-7e2d-4548-89e6-8647400f4448","name":"Out of scope","targets":[{"id":"decd2acb-df60-4c95-be33-f1e725c7553a","uri":null,"name":"Corporate Email (*@skyscanner.net)","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"97ce9f74-ab22-47a8-97de-b811461b1f62","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"b1e8c462-32b2-416c-b7ad-1bd65baf9ff3","uri":"https://help.skyscanner.net","name":"help.skyscanner.net","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5ddac2eb-e2d6-41ca-b559-c6edd6e58651","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null},{"id":"2f400c9a-63d3-4f1e-91f7-d877124d0b0f","uri":"https://carhirehelp.skyscanner.net","name":"carhirehelp.skyscanner.net","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b24f3ed5-1780-4150-ad74-5dc73e6ae45b","sortOrder":2},"sortOrder":2,"tags":null,"recentChangeFlags":null},{"id":"2655a42e-55a0-40ef-97ab-4ae2f183eea0","uri":"https://hotelshelp.skyscanner.net","name":"hotelshelp.skyscanner.net","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"6503ae7c-635c-445e-8f74-388413cb9325","sortOrder":3},"sortOrder":3,"tags":null,"recentChangeFlags":null},{"id":"34c27588-3a3b-4c38-b864-65eaf1810b4a","uri":"https://support.business.skyscanner.net","name":"support.business.skyscanner.net","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"65d036f5-4569-4a93-a2d7-53753aff1eaf","sortOrder":4},"sortOrder":4,"tags":null,"recentChangeFlags":null},{"id":"e3be4e0b-e59e-4e07-917a-ee3a7654ab6e","uri":"https://www.partners.skyscanner.net","name":"www.partners.skyscanner.net","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f690e2ec-ac76-49f6-bf9b-c13d8afb607e","sortOrder":5},"sortOrder":5,"tags":null,"recentChangeFlags":null},{"id":"1b00e287-c75b-4264-8ca8-a4b6d913fa0c","uri":"https://creators.skyscanner.net","name":"creators.skyscanner.net","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"a3ea10d6-3e22-42bd-a3e4-eb0645eee80c","sortOrder":6},"sortOrder":6,"tags":null,"recentChangeFlags":null},{"id":"d06ceefb-d463-40f5-acaa-2c02e675192a","uri":"https://preferences.skyscanner.net","name":"preferences.skyscanner.net","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"fbdacdaf-df51-4892-b879-870b7cc39182","sortOrder":7},"sortOrder":7,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":3,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[{"id":"f2464603-a480-4f00-ae85-afe81d880ef2","attachmentPath":"https://bugcrowd.com/engagements/skyscanner/attachments/f2464603-a480-4f00-ae85-afe81d880ef2","name":"image003.jpg","filename":"image003.jpg","description":null,"icon":"fileImage","size":166321,"sizeLabel":"162 KB","uploadedAt":"6 Aug 2024","fileType":"Image","embedUrl":"https://bugcrowd.com/engagements/skyscanner/attachments/f2464603-a480-4f00-ae85-afe81d880ef2"},{"id":"e666881d-9bb6-4582-a4c7-4f3a6866450c","attachmentPath":"https://bugcrowd.com/engagements/skyscanner/attachments/e666881d-9bb6-4582-a4c7-4f3a6866450c","name":"image004.jpg","filename":"image004.jpg","description":null,"icon":"fileImage","size":217039,"sizeLabel":"212 KB","uploadedAt":"6 Aug 2024","fileType":"Image","embedUrl":"https://bugcrowd.com/engagements/skyscanner/attachments/e666881d-9bb6-4582-a4c7-4f3a6866450c"},{"id":"8a12c35b-dba5-467c-a82d-58640aa51261","attachmentPath":"https://bugcrowd.com/engagements/skyscanner/attachments/8a12c35b-dba5-467c-a82d-58640aa51261","name":"image001.jpg","filename":"image001.jpg","description":null,"icon":"fileImage","size":183914,"sizeLabel":"180 KB","uploadedAt":"6 Aug 2024","fileType":"Image","embedUrl":"https://bugcrowd.com/engagements/skyscanner/attachments/8a12c35b-dba5-467c-a82d-58640aa51261"},{"id":"8cea2284-3a27-47fd-a65c-2ac042f2da14","attachmentPath":"https://bugcrowd.com/engagements/skyscanner/attachments/8cea2284-3a27-47fd-a65c-2ac042f2da14","name":"image002.jpg","filename":"image002.jpg","description":null,"icon":"fileImage","size":164009,"sizeLabel":"160 KB","uploadedAt":"6 Aug 2024","fileType":"Image","embedUrl":"https://bugcrowd.com/engagements/skyscanner/attachments/8cea2284-3a27-47fd-a65c-2ac042f2da14"},{"id":"94c805db-df0b-4fe6-abf1-3f9edf1beaa5","attachmentPath":"https://bugcrowd.com/engagements/skyscanner/attachments/94c805db-df0b-4fe6-abf1-3f9edf1beaa5","name":"image006.jpg","filename":"image006.jpg","description":null,"icon":"fileImage","size":211549,"sizeLabel":"207 KB","uploadedAt":"6 Aug 2024","fileType":"Image","embedUrl":"https://bugcrowd.com/engagements/skyscanner/attachments/94c805db-df0b-4fe6-abf1-3f9edf1beaa5"},{"id":"7395e87a-20cf-41d3-b2ec-afc58138cda1","attachmentPath":"https://bugcrowd.com/engagements/skyscanner/attachments/7395e87a-20cf-41d3-b2ec-afc58138cda1","name":"image005.jpg","filename":"image005.jpg","description":null,"icon":"fileImage","size":156666,"sizeLabel":"153 KB","uploadedAt":"6 Aug 2024","fileType":"Image","embedUrl":"https://bugcrowd.com/engagements/skyscanner/attachments/7395e87a-20cf-41d3-b2ec-afc58138cda1"},{"id":"04cc2962-cff1-427b-bbf6-06b61f06f136","attachmentPath":"https://bugcrowd.com/engagements/skyscanner/attachments/04cc2962-cff1-427b-bbf6-06b61f06f136","name":"image007.jpg","filename":"image007.jpg","description":null,"icon":"fileImage","size":144745,"sizeLabel":"141 KB","uploadedAt":"6 Aug 2024","fileType":"Image","embedUrl":"https://bugcrowd.com/engagements/skyscanner/attachments/04cc2962-cff1-427b-bbf6-06b61f06f136"}],"engagement":{"id":"eb6c41e5-20d5-4fcc-8927-25f3ebcf6c0c","code":"skyscanner","state":"in_progress","endsAt":null,"bountyId":"be7b7b42-924a-41f1-8e20-d73f3ce7ea7c","startsAt":"2018-11-27T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Consumer Services","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/f385/4e29/59412af3/0ec567cf519e0103e54b114559943588_square_logo.png","logoBackgroundColor":"#0770e3","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2018-11-27T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/skyscanner","changelogs":"/engagements/skyscanner/changelog","submissions":null,"announcements":"/engagements/skyscanner/announcements","hallOfFame":"/engagements/skyscanner/hall_of_fames","crowdstream":"/engagements/skyscanner/crowdstream"},"announcementsCount":8,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/skyscanner/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=skyscanner\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/skyscanner/engagement_subscribers","engagementChangelogsUrl":"/engagements/skyscanner/changelog","publishedAt":"2026-07-24T10:20:34.086Z","engagementChangelogUrl":"/engagements/skyscanner/changelog/2c1e110f-7462-40b2-9539-13e36cd1dd1d","createUserFeedbacksUrl":"/engagements/skyscanner/feedbacks","engagementCrowdstreamUrl":"/engagements/skyscanner/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}