{"id":"3df77fd4-c895-4c37-828f-3ce2f1c1b99a","engagementId":"52215371-526f-4ce5-aa61-54f35a506c04","data":{"brief":{"id":"68f1439a-9ced-427e-86fe-9a421c2374b3","name":"TNS Vulnerability Disclosure Engagement","tagline":"TNS, a global provider of IaaS solutions, supports thousands of organizations across 60 countries in efficient, secure, and flexible technology adoption.","description":"\u003cp\u003eNo technology is perfect and TNS believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our assets. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this engagement will use the\u003c/em\u003e \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" title=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003e\u003cem\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/em\u003e\u003c/a\u003e\u003cem\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":"2b678620-ffdb-439a-8bac-c91b0087e0a0","targetsOverview":"\u003ch2\u003eRatings\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this engagement will use the\u003c/em\u003e \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" title=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003e\u003cem\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/em\u003e\u003c/a\u003e\u003cem\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch3\u003eCredentials\u003c/h3\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" title=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e. \u003c/p\u003e\n\n\u003ch3\u003eTNS Vulnerability Disclosure Policy\u003c/h3\u003e\n\n\u003cp\u003eAt TNS, protecting the information of our customers, partners, vendors, employees, and organization is a top priority. We value the important role that customers, security researchers, and security experts play in helping us safeguard our systems. We encourage responsible disclosure of vulnerabilities in accordance with this policy and appreciate the opportunity to promptly investigate and remediate findings.\u003cbr\u003e\nThis policy explains:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhich systems and types of research are covered.\u003c/li\u003e\n\u003cli\u003eHow to report vulnerabilities to TNS.\u003c/li\u003e\n\u003cli\u003eHow long we ask researchers to wait before public disclosure.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eRules of Engagement\u003c/h3\u003e\n\n\u003cp\u003eBy participating in our Vulnerability Disclosure Program, you agree to act in good faith and to:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eFollow this policy and any other applicable agreements. If there is a conflict, this policy takes precedence.\u003c/li\u003e\n\u003cli\u003eReport vulnerabilities promptly.\u003c/li\u003e\n\u003cli\u003eAvoid violating privacy, disrupting systems, destroying data, or degrading the user experience.\u003c/li\u003e\n\u003cli\u003eUse only official reporting channels.\u003c/li\u003e\n\u003cli\u003eAllow a reasonable period (at least 90 days from the initial report) for remediation before public disclosure.\u003c/li\u003e\n\u003cli\u003eTest only in-scope systems and respect all out-of-scope systems.\u003c/li\u003e\n\u003cli\u003eLimit data access strictly to what is required to demonstrate a Proof of Concept. If you encounter sensitive data (e.g., PII, PHI, credit card data, or proprietary information), stop testing immediately and submit a report.\u003c/li\u003e\n\u003cli\u003eUse only test accounts you own or those for which you have explicit permission.\u003c/li\u003e\n\u003cli\u003eRefrain from any form of extortion.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eProhibited Activities\u003c/h3\u003e\n\n\u003cp\u003eTo protect our users and systems, you must not:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAccess or attempt to access accounts or data that do not belong to you.\u003c/li\u003e\n\u003cli\u003eView, modify, delete, or destroy data.\u003c/li\u003e\n\u003cli\u003ePerform denial-of-service testing or introduce malware.\u003c/li\u003e\n\u003cli\u003eUse exploits beyond what is necessary to confirm a vulnerability. This includes attempting to exfiltrate data, gain persistence, establish command-line access, or pivot to other systems.\u003c/li\u003e\n\u003cli\u003eContinue testing once a vulnerability is confirmed or sensitive data is encountered.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eTesting Requirements\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eMonitor your testing carefully to avoid impacting system performance or availability.\u003c/li\u003e\n\u003cli\u003eIf you notice degradation of our assets, stop all testing immediately and suspend automated tools.\u003c/li\u003e\n\u003cli\u003eKeep vulnerability details confidential for at least 90 calendar days after Bugcrowd validation.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eScope\u003c/h3\u003e\n\n\u003cp\u003eThis policy applies to:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDomains owned by TNS and its brands/subsidiaries \u003c/li\u003e\n\u003cli\u003eAll hardware products and associated software engineered, developed, and manufactured by TNS, any brand, or any subsidiary\u003c/li\u003e\n\u003cli\u003eAll applications published on Google Play or Apple App Store associated with TNS, its brands, or subsidiaries\u003c/li\u003e\n\u003cli\u003eAny associated infrastructure vulnerabilities\u003c/li\u003e\n\u003cli\u003eOther TNS-owned assets with demonstrated security impact\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eOut of Scope\u003c/h3\u003e\n\n\u003cp\u003eIf you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to TNS, you can report it to this engagement. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eDenial-of-service testing (DoS/DDoS).\u003c/li\u003e\n\u003cli\u003ePhysical security testing (e.g., office access, tailgating).\u003c/li\u003e\n\u003cli\u003eSocial engineering (e.g., phishing, vishing, spam).\u003c/li\u003e\n\u003cli\u003eSelf-XSS.\u003c/li\u003e\n\u003cli\u003eMalware uploads.\u003c/li\u003e\n\u003cli\u003eVulnerabilities in non-TNS vendor systems (report directly to the vendor).\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eIf you are unsure whether a system or endpoint is in scope, contact us at TNS-vdp-pro@submit.bugcrowd.com before starting your research.\u003c/p\u003e\n\n\u003ch3\u003eReporting a Vulnerability\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eTNS accepts and reviews reports through Bugcrowd’s submission form (preferred). This ensures your report includes the details we need to validate and remediate quickly.\u003c/li\u003e\n\u003cli\u003eAlternatively, you may submit by email to TNS-vdp-pro@submit.bugcrowd.com.\u003c/li\u003e\n\u003cli\u003eWe may share reports with US-CERT, affected vendors, or open-source projects, where appropriate. Please note that third-party systems are out of scope and should be reported directly to those vendors.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eCoordinated Disclosure\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eTNS is committed to remediating validated vulnerabilities within 90 days or fewer of Bugcrowd validation.\u003c/li\u003e\n\u003cli\u003ePlease do not share your report with others until remediation is complete.\u003c/li\u003e\n\u003cli\u003eIf you wish to publish an advisory, we ask that you coordinate with us so sensitive details can be redacted, and we have time to review before public posting.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eEligibility\u003c/h3\u003e\n\n\u003cp\u003eParticipants must:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNot be residents of countries under U.S. sanctions (as listed by the U.S. Treasury Department).\u003c/li\u003e\n\u003cli\u003eNot be current or recent (within the past 6 months) employees or contractors of TNS or its subsidiaries.\u003c/li\u003e\n\u003cli\u003eEnsure research complies with U.S. law and the laws of your country of residence.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eOur Commitment\u003c/h3\u003e\n\n\u003cp\u003eWe will:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eReview and validate your report through Bugcrowd.\u003c/li\u003e\n\u003cli\u003eTreat validated findings as a top remediation priority.\u003c/li\u003e\n\u003cli\u003eProvide updates throughout the submission, validation, and remediation process.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eSafe Harbor\u003c/h3\u003e\n\n\u003cp\u003eWhen conducting vulnerability research in accordance with this policy, we consider your activity to be:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized under the Computer Fraud and Abuse Act (CFAA) and similar laws.\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA).\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would otherwise interfere with security research.\u003c/li\u003e\n\u003cli\u003eLawful, helpful to Internet security, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eIf you have any doubts about whether your research is consistent with this policy, please create a ticket with Bugcrowd Support before proceeding.\u003c/li\u003e\n\u003c/ul\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"c2f0f9dd-510f-41cd-adcc-098c8dc27508","name":"In Scope","targets":[{"id":"75bf66ce-c93f-4114-adad-a699838b9ca7","uri":"","name":"*.TNSI.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"7436c89a-4d34-4aaf-9035-73d6e72fce72","sortOrder":0},"sortOrder":0,"tags":[{"id":"487e9af0-2610-4813-a092-ea46f4cb6de1","name":"Wordpress","targetId":"75bf66ce-c93f-4114-adad-a699838b9ca7"},{"id":"5644ab16-c7ca-4ff7-ac95-383343dab77f","name":"MySQL","targetId":"75bf66ce-c93f-4114-adad-a699838b9ca7"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"75bf66ce-c93f-4114-adad-a699838b9ca7"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"75bf66ce-c93f-4114-adad-a699838b9ca7"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"75bf66ce-c93f-4114-adad-a699838b9ca7"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"75bf66ce-c93f-4114-adad-a699838b9ca7"}],"recentChangeFlags":null},{"id":"f518d936-ea37-4b25-8c62-7330805630a1","uri":"https://www.commonlanguage.com/","name":"Commonlanguage.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"2314616b-4802-449c-8fe6-7977e0c74b51","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null},{"id":"654430a4-c6da-4907-996c-901c6482b1d0","uri":"https://ukonetouchswitch.com/","name":"UKonetouchswitch.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"3cd95068-2722-4f23-9b4b-d06114626ddd","sortOrder":2},"sortOrder":2,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"52215371-526f-4ce5-aa61-54f35a506c04","code":"tns-vdp-pro","state":"in_progress","endsAt":null,"bountyId":"84308e19-f440-45c5-97a6-c2c4f2065406","startsAt":"2025-09-30T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Telecommunications","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/39b0/da45/e8aaf07b/e333699998f0659f3aa3f8064b44b419_tns_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-09-30T18:00:00.034Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/tns-vdp-pro","changelogs":"/engagements/tns-vdp-pro/changelog","submissions":null,"announcements":"/engagements/tns-vdp-pro/announcements","hallOfFame":"/engagements/tns-vdp-pro/hall_of_fames","crowdstream":"/engagements/tns-vdp-pro/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/tns-vdp-pro/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=tns-vdp-pro\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/tns-vdp-pro/engagement_subscribers","engagementChangelogsUrl":"/engagements/tns-vdp-pro/changelog","publishedAt":"2026-09-15T18:25:30.652Z","engagementChangelogUrl":"/engagements/tns-vdp-pro/changelog/3df77fd4-c895-4c37-828f-3ce2f1c1b99a","createUserFeedbacksUrl":"/engagements/tns-vdp-pro/feedbacks","engagementCrowdstreamUrl":"/engagements/tns-vdp-pro/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}