{"id":"fe08c7af-8157-4dd9-a9e9-35f7df17507c","engagementId":"7c0eec32-8812-4eaf-838c-001d600d45b7","data":{"brief":{"id":"ba62f584-afd3-4990-b7d3-709177d4d1aa","name":"Tamedia","tagline":"TX Group is the leading private media group in Switzerland. Belonging to TX Group, Tamedia is the business unit responsible for the Paid Media.","description":"\u003cp\u003eTX Group is the leading private media group in Switzerland. Belonging to TX Group, Tamedia is the business unit responsible for the Paid Media. We produce daily newspapers, Sunday newspapers and magazines, reaching Switzerland's entire population. Digital represents a core component of our current strategy, with all our newspapers featuring robust digital platforms alongside their print versions.\u003c/p\u003e\n\n\u003cp\u003eSecurity remains paramount in our operation, therefore we've established a Bug Bounty Program to ensure security is embedded from the ground up. \u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003ePlease note that testing should only be conducted on our current production environment - do not perform any testing against legacy systems.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003eGood luck and happy hunting.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003ePlease carefully read the scope description. Currently, submissions are accepted for \u003ccode\u003ewww.inscopedomain.ch\u003c/code\u003e and non-authenticated testing only!\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"ef2b9ee7-7f73-4978-9530-ad18bbf3f902","targetsOverview":"\u003ch3\u003eTesting is only authorized on the targets listed as In-Scope. Any domain/property of Paid-Media Frontends not listed in the targets section is out of scope. This includes any/all subdomains not listed above.  IF you happen to identify a security vulnerability on a target that is not in-scope, but that demonstrably belongs to Paid-Media Frontends, it may be reported to this program, and is appreciated - but will ultimately be marked as ‘not applicable’ and will not be eligible for monetary or points-based compensation.\u003c/h3\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eTarget Information:\u003c/h2\u003e\n\n\u003cp\u003eThe target environment is production, running on AWS (Node.JS) and MongoDB Atlas. \u003cbr\u003e\n\u003cstrong\u003ePlease note, the targets are all running on the same service. They share a codebase. If a vulnerability is valid for one it will be valid for all and only a single unique issue will be accepted as valid. Any submission involving the same vulnerability will be considered duplicated.\u003c/strong\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eCredentials:\u003c/h3\u003e\n\n\u003ch4\u003eCurrently authenticated testing is out of scope. Please do not sign up for any accounts as anything submitted that was found via authenticated testing will be marked as out of scope.\u003c/h4\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut-of-Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eLegacy Paid-Media Frontend websites\u003c/li\u003e\n\u003cli\u003eSubdomain Takeover\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eDMARC, SPF, DKIM issues\u003c/li\u003e\n\u003cli\u003eAuthenticated testing \u0026amp; sign ups\u003c/li\u003e\n\u003cli\u003eOther domains, subdomains or paths not listed in the targets section\u003c/li\u003e\n\u003cli\u003eiOS and Android apps\u003c/li\u003e\n\u003cli\u003eRate-limiting or (D)DoS attack related submissions\u003c/li\u003e\n\u003cli\u003eAggressive automated scans as these will most likely lock you out (by AWS)\u003c/li\u003e\n\u003cli\u003eAttacks requiring physical access to a user's device.\u003c/li\u003e\n\u003cli\u003eAll third party applications or libraries/dependencies not under control by Tamedia\u003c/li\u003e\n\u003cli\u003eVulnerabilities affecting users of outdated browsers or platforms.\u003c/li\u003e\n\u003cli\u003eCookies missing secure or HttpOnly.\u003c/li\u003e\n\u003cli\u003eClickjacking and issues only exploitable through clickjacking.\u003c/li\u003e\n\u003cli\u003eBroken Link Hijacking falls outside the purview of our monitoring protocol. Given the vast number of journalists and articles within our organization, it is not feasible for us to ensure that all links within our website lead to non-compromised destinations. While we do accept reports for broken links located in the footer or other static sections of our website, it is important to note that addressing broken link hijacking is not within the scope of our current program.\u003c/li\u003e\n\u003cli\u003eMissing or not perfectly secured HTTP security headers, specifically (\u003ca href=\"https://owasp.org/www-project-secure-headers/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://owasp.org/www-project-secure-headers/\u003c/a\u003e), e.g.\n\n\u003cul\u003e\n\u003cli\u003eStrict-Transport-Security.\u003c/li\u003e\n\u003cli\u003eX-Frame-Options.\u003c/li\u003e\n\u003cli\u003eX-XSS-Protection.\u003c/li\u003e\n\u003cli\u003eX-Content-Type-Options.\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy, X-Content-Security-Policy, X-WebKit-CSP.\u003c/li\u003e\n\u003cli\u003eContent-Security-Policy-Report-Only.\u003c/li\u003e\n\u003cli\u003eCache-Control and Pragma\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"26c6f6b4-c8bf-41a0-a696-04d53e10137c","name":"Paid-Media Frontends ","targets":[{"id":"e8284fa3-7230-4882-a5c2-4d4767d3e03c","uri":"https://www.tagesanzeiger.ch","name":"https://www.tagesanzeiger.ch","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"513d8aee-e25b-4bc6-9541-1804c73a553b","sortOrder":0},"sortOrder":0,"tags":[{"id":"a41318b7-d0b8-4b39-8250-dbbad194e770","name":"MongoDB","targetId":"e8284fa3-7230-4882-a5c2-4d4767d3e03c"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"e8284fa3-7230-4882-a5c2-4d4767d3e03c"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"e8284fa3-7230-4882-a5c2-4d4767d3e03c"}],"recentChangeFlags":null},{"id":"53f48fa3-d653-4a62-8426-ed86245973ac","uri":"","name":"API calls going to disco-api from https://www.tagesanzeiger.ch ","category":"api","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"928c674e-41bc-429e-80cb-ebfd710db637","sortOrder":1},"sortOrder":1,"tags":[{"id":"1f2fc0ed-8b79-47a2-a6dc-564a2d9d0828","name":"API Testing","targetId":"53f48fa3-d653-4a62-8426-ed86245973ac"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"b406db1d-2bcf-452b-aeab-51f79047bc0d","p1MaxCents":250000,"p1MinCents":210000,"p2MaxCents":125000,"p2MinCents":100000,"p3MaxCents":60000,"p3MinCents":45000,"p4MaxCents":20000,"p4MinCents":15000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":2100,"max":2500},"2":{"min":1000,"max":1250},"3":{"min":450,"max":600},"4":{"min":150,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"28651657-52b2-436e-b372-052a11eb7b9f","name":"Out of scope targets","targets":[{"id":"6246b1c9-7581-4a76-9acc-cbf7cf623a58","uri":"https://abo.inscopedomain.ch","name":"https://abo.inscopedomain.ch","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"b8ba1cad-3cfd-4e14-ac8e-8002c5570533","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"2e8a5d44-b62e-4617-bba4-ffdb0d0e2344","uri":"","name":"https://login.inscopedomain.ch/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"c8d9d080-1dec-40c6-b927-97106efc026a","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2e8a5d44-b62e-4617-bba4-ffdb0d0e2344"}],"recentChangeFlags":null},{"id":"87dfbaea-ab0a-4cb5-ba2a-8f02ec02c394","uri":"","name":"https://auth.inscopedomain.ch/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"103e333f-f811-47de-853e-5be49677eb2e","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"87dfbaea-ab0a-4cb5-ba2a-8f02ec02c394"}],"recentChangeFlags":null},{"id":"b872de4b-47ff-4252-945f-b47f717f458a","uri":"","name":"https://tgt.inscopedomain.ch/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"752ac479-8a3d-4380-82a7-4856eb72bd27","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"b872de4b-47ff-4252-945f-b47f717f458a"}],"recentChangeFlags":null},{"id":"da99b41d-2458-46a8-ac19-05cb587f90db","uri":"","name":"https://shop.inscopedomain.ch/","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"64ad3f81-bed5-421f-b564-d4716e143997","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"da99b41d-2458-46a8-ac19-05cb587f90db"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"7c0eec32-8812-4eaf-838c-001d600d45b7","code":"tamedia","state":"in_progress","endsAt":null,"bountyId":"8f120db7-80d2-4c4a-8352-94d1ba054b84","startsAt":"2020-09-29T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Entertainment","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/e2d8/64a5/08ae88fc/3f28dbf0311641e9869c7bc7f624899f_logo_tamedia_red.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-08-18T07:02:39.937Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/tamedia","changelogs":"/engagements/tamedia/changelog","submissions":null,"announcements":"/engagements/tamedia/announcements","hallOfFame":"/engagements/tamedia/hall_of_fames","crowdstream":"/engagements/tamedia/crowdstream"},"announcementsCount":4,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/tamedia/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=tamedia\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/tamedia/engagement_subscribers","engagementChangelogsUrl":"/engagements/tamedia/changelog","publishedAt":"2025-08-18T07:05:30.607Z","engagementChangelogUrl":"/engagements/tamedia/changelog/fe08c7af-8157-4dd9-a9e9-35f7df17507c","createUserFeedbacksUrl":"/engagements/tamedia/feedbacks","engagementCrowdstreamUrl":"/engagements/tamedia/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}