{"id":"3cb4c110-060e-46e4-a7f0-bb26ea3507c1","engagementId":"d988a5f1-ecce-4d8c-9edf-515896c07554","data":{"brief":{"id":"6cc8a829-9af0-4b3e-9910-f5641c75d4f0","name":"Tyler Technologies Data \u0026 Insights – Tyler Data Platform, powered by Socrata","tagline":"Put your skills to the test!","description":"\u003cp\u003eTyler Technologies Data \u0026amp; Insights helps public sector organizations improve transparency, citizen service, and data-driven decision-making. Our user-friendly solutions deliver data to governments trying to reduce costs, to citizens who want to understand how their tax dollars are used, and to civic hackers dedicated to creating new apps and improving services.\u003c/p\u003e\n\n\u003cp\u003eWe take the security of our systems seriously, and we value the security researcher community. The disclosure of security vulnerabilities by security researchers helps us ensure the security and privacy of our users and makes the Web a safer place for all.\u003c/p\u003e\n\n\u003cp\u003eBecause our platform is built for data sharing it is worthwhile for researchers to familiarize themselves with the account permission models in place and especially with our Socrata Query Language (SoQL).\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eA note on SoQL\u003c/strong\u003e: SoQL is a read-only, public query interface available on open data endpoints. It supports filtering, sorting, and arithmetic through URL parameters like $select, $where, and $query. These are intentional platform features, not vulnerabilities. Before submitting any injection-related finding on a Socrata endpoint, please confirm you are testing against a private or privileged resource and not the public SoQL API.\u003c/p\u003e\n\n\u003cp\u003eGood luck and happy hunting! \u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eDuplicate and same root cause policy\u003c/strong\u003e: Findings that share the same root cause and remediation path will be consolidated into a single finding for reward purposes, regardless of the number of affected endpoints. If multiple submissions from the same researcher share a root cause, we will notify the researcher and process one reward.\u003c/p\u003e","industryTagId":"02370343-bf13-4661-a7a2-caa1c1076ad1","targetsOverview":"\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as In-Scope. Any domain/property of Socrata not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in-scope, but that demonstrably belongs to Socrata, it may be reported to this program, and is appreciated - but will ultimately be marked as 'not applicable' and will not be eligible for monetary or points-based compensation.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003eNote that leaked API keys and credential submissions are welcomed, however, we do not permit these to be tested by researchers prior to submission. Additionally, please do not submit credentials that appear to be related to unit testing or other early software development lifecycle stages as these typically do not carry any risk and will not be rewarded. Note that Socrata will have the final say on impact once they review any submitted API keys or credentials.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eEngagement Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWe strictly prohibit usage of Automated scanners - we have our own DAST :)\u003c/li\u003e\n\u003cli\u003eScripted verification of a specific, already-identified finding across a limited set of endpoints is permitted within the testing window. Mass enumeration or automated discovery of new findings is not.\u003c/li\u003e\n\u003cli\u003eAll testing should be limited to 0700-1800 PDT (GMT -7) - this helps our on-call staff stay sane :)\u003c/li\u003e\n\u003cli\u003eMake every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction of data during security testing\u003c/li\u003e\n\u003cli\u003ePerform research only within the scope set out below\u003c/li\u003e\n\u003cli\u003eUse the identified communication channels to report vulnerability information to us\u003c/li\u003e\n\u003cli\u003eKeep information about any vulnerabilities you’ve discovered confidential between yourself and Socrata\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eIf you follow these guidelines when reporting an issue to us we commit to:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eNot institute a civil legal action against you and not support a criminal investigation\u003c/li\u003e\n\u003cli\u003eWork with you to understand and resolve the issue quickly (confirming the report within one week of submission)\u003c/li\u003e\n\u003cli\u003eRecognize your contribution on our Security Researcher Hall of Fame, if you are the first to report the issue and we make a code or configuration change based on the issue\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eThank you for participating and happy hunting!\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eGetting Started - General Usage\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eCreate a primary account at:\u003c/strong\u003e \u003ca href=\"https://opendata.test-socrata.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehttps://opendata.test-socrata.com/\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003ePlease use the following format: username@bugcrowdninja.com\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eExample: bugcrowd_01@bugcrowdninja.com\u003c/li\u003e\n\u003cli\u003eThis will forward email to your registered Bugcrowd email address\u003c/li\u003e\n\u003cli\u003eDisplay name = Bugcrowd (unique name)\u003c/li\u003e\n\u003cli\u003eExample = Bugcrowd Jane\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eCreate a secondary account [to test account and data integrity]\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003ePlease use the following format: email: name+bugcrowd@domain.com\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eExample: joe+bugcrowd@hotmail.com\u003c/li\u003e\n\u003cli\u003eDisplay name = Bugcrowd (unique name)\u003c/li\u003e\n\u003cli\u003eExample = Bugcrowd Jane02\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eIf you are able to compromise any datasets or accounts to the point where you would be able to modify the data \u003cstrong\u003eDO NOT DO SO\u003c/strong\u003e. Let us know and we'll create a test dataset for you to try the changes on.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eAccess Control Vulnerabilities\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePublic or anonymous user access to non-public resources (i.e. Private drafts)\u003c/li\u003e\n\u003cli\u003eRoled user access to restricted-role resources (i.e. accessing Private drafts not shared with that user)\u003c/li\u003e\n\u003cli\u003eAPI endpoints returning private user data (e.g., email addresses, private file metadata, account details) to unauthenticated or low-privilege callers due to a missing authorization check. \nPublicly visible profile fields such as display names are not in scope under this item.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eConfidentiality Impact (private data access or leakage)\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eServer-side Remote Code Execution (RCE)\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eSQL Injection (SQLi) - Note: Please see notes on SQL vs. SoQL below before reporting SQLi\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003ePath/Directory Traversal Issues\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eStored XSS that executes in another user's browser session. Self-XSS (where the attacker and victim must be the same account) is excluded, regardless of whether the payload is triggered through normal application functionality or requires atypical steps (e.g., browser console injection).\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eCORS misconfiguration (e.g., Access-Control-Allow-Origin: *) on endpoints serving only public, unauthenticated, read-only data, where no authentication or authorization is bypassed as a result.\u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eAuthentication control bypass where a supported auth mechanism (e.g., Basic Auth, API keys) circumvents a security control that should apply platform-wide, \u003cbr\u003e\nsuch as MFA requirements or cross-origin request restrictions.\u003c/p\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut of Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAny customer sites hosted on the Socrata platform are explicitly off-limits.\u003c/li\u003e\n\u003cli\u003eAny services hosted by 3rd party providers and services are excluded from scope. These services include:\n\n\u003cul\u003e\n\u003cli\u003eThird-party add-ons\u003c/li\u003e\n\u003cli\u003es3.amazon.com\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eThe following finding types are specifically excluded from the bounty and are things we do not want to see:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003ePersonally identifiable information of users (PII) that you may have found during your research\u003c/li\u003e\n\u003cli\u003eOutput from a commercial or commonly available scanning tool. We know.\u003c/li\u003e\n\u003cli\u003eSeriously, don't try to brute-force other user accounts.\u003c/li\u003e\n\u003cli\u003eBug reports coming through any channels other than Bugcrowd. Do not file support tickets at support.socrata.com or e-mail our support staff. Please use the Bugcrowd portal.\u003c/li\u003e\n\u003cli\u003eFindings from applications or systems not listed in the ‘Targets’ section\u003c/li\u003e\n\u003cli\u003eFunctional, UI and UX bugs and spelling mistakes\u003c/li\u003e\n\u003cli\u003eNetwork and Application level Denial of Service (DoS/DDoS) vulnerabilities\u003c/li\u003e\n\u003cli\u003eClickjacking and issues only exploitable through clickjacking.\u003c/li\u003e\n\u003cli\u003eCSRF attacks that require knowledge of the CSRF token (e.g. attacks involving a local machine).\u003c/li\u003e\n\u003cli\u003eContent Spoofing.\u003c/li\u003e\n\u003cli\u003eLogin or Forgot Password page brute force and account lockout not enforced.\u003c/li\u003e\n\u003cli\u003eUsername or email enumeration via login, registration, or password reset flows. \nNote: API endpoints that expose user emails due to a missing access control are in scope under Access Control Vulnerabilities above.\u003c/li\u003e\n\u003cli\u003eReflected payloads appearing exclusively in application/json API responses where the Content-Type is not HTML and the response cannot be rendered as a web page.\nIf the same endpoint returns HTML under any conditions, this exclusion does not apply.\u003c/li\u003e\n\u003cli\u003eMissing HTTP security headers, e.g.\n\n\u003cul\u003e\n\u003cli\u003eCache-Control and Pragma\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eNo Load testing (DoS/DDoS etc) is allowed.\n\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eThis includes application DoS as well as network DoS.\u003c/strong\u003e\u003c/li\u003e\n\u003cli\u003eVulnerabilities that are limited to unsupported browsers will not be accepted.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eMissing or incorrect DMARC records of any kind.\u003c/li\u003e\n\u003cli\u003eSource code disclosure vulnerabilities.\u003c/li\u003e\n\u003cli\u003eInformation disclosure of non-confidential information (e. g. issue id, project id, commit hashes).\u003c/li\u003e\n\u003cli\u003eEmail bombing/Flooding/rate limiting\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"e224d73a-c786-4b6f-9d6a-72ea622f436b","name":"In Scope ","targets":[{"id":"5cb2ec95-d356-426b-b8f2-81743cb9b0a0","uri":"https://opendata-demo.test-socrata.com","name":"https://opendata-demo.test-socrata.com","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"1921334e-b84a-4905-9552-78580ebda564","sortOrder":0},"sortOrder":0,"tags":[{"id":"4e9d5c53-3b04-4bca-ba30-e8e33d87019a","name":"Ruby on Rails","targetId":"5cb2ec95-d356-426b-b8f2-81743cb9b0a0"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"5cb2ec95-d356-426b-b8f2-81743cb9b0a0"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"5cb2ec95-d356-426b-b8f2-81743cb9b0a0"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"5cb2ec95-d356-426b-b8f2-81743cb9b0a0"}],"recentChangeFlags":null},{"id":"37b61fa1-4299-4662-9b77-ddd84710b1e0","uri":"https://opendata.test-socrata.com","name":"https://opendata.test-socrata.com","category":"other","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e126a467-1b13-476b-b798-922d4dff5c22","sortOrder":0},"sortOrder":0,"tags":[{"id":"4e9d5c53-3b04-4bca-ba30-e8e33d87019a","name":"Ruby on Rails","targetId":"37b61fa1-4299-4662-9b77-ddd84710b1e0"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"37b61fa1-4299-4662-9b77-ddd84710b1e0"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"37b61fa1-4299-4662-9b77-ddd84710b1e0"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"37b61fa1-4299-4662-9b77-ddd84710b1e0"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"b406db1d-2bcf-452b-aeab-51f79047bc0d","p1MaxCents":250000,"p1MinCents":210000,"p2MaxCents":125000,"p2MinCents":100000,"p3MaxCents":60000,"p3MinCents":45000,"p4MaxCents":20000,"p4MinCents":15000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eDocumentation\u003c/h2\u003e\n\n\u003cp\u003e\u003ca href=\"https://support.socrata.com/hc/en-us\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eGetting Started - UI Usage\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://dev.socrata.com/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eGetting Started - API Testing\u003c/a\u003e\u003c/p\u003e","rewardRangeData":{"1":{"min":2100,"max":2500},"2":{"min":1000,"max":1250},"3":{"min":450,"max":600},"4":{"min":150,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"d988a5f1-ecce-4d8c-9edf-515896c07554","code":"tyler-tech-data-insights","state":"in_progress","endsAt":null,"bountyId":"8b11efc9-73e7-448a-95d8-cf4c2d7747a8","startsAt":"2015-06-23T16:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Computer Software","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/04c0/1f22/fbcee57c/5b398460220a42c28f675778b145457e_tylertech.jpeg","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2015-06-23T16:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/tyler-tech-data-insights","changelogs":"/engagements/tyler-tech-data-insights/changelog","submissions":null,"announcements":"/engagements/tyler-tech-data-insights/announcements","hallOfFame":"/engagements/tyler-tech-data-insights/hall_of_fames","crowdstream":"/engagements/tyler-tech-data-insights/crowdstream"},"announcementsCount":4,"knownIssuesEnabled":false,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/tyler-tech-data-insights/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=tyler-tech-data-insights\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/tyler-tech-data-insights/engagement_subscribers","engagementChangelogsUrl":"/engagements/tyler-tech-data-insights/changelog","publishedAt":"2026-08-26T18:41:33.999Z","engagementChangelogUrl":"/engagements/tyler-tech-data-insights/changelog/3cb4c110-060e-46e4-a7f0-bb26ea3507c1","createUserFeedbacksUrl":"/engagements/tyler-tech-data-insights/feedbacks","engagementCrowdstreamUrl":"/engagements/tyler-tech-data-insights/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}