{"id":"99b04282-0f12-4f72-81a8-fab3bdfd90d7","engagementId":"261fb647-f15f-4f6a-8d97-4856d8ad6907","data":{"brief":{"id":"3d036f75-9e80-40be-96a8-ccb6e0a28ab3","name":"Ulta Beauty Vulnerability Disclosure Program","tagline":"Ulta Beauty is the largest U.S. beauty retailer and the premier beauty destination for various services. ","description":"\u003cp\u003eAt Ulta Beauty, the possibilities are beautiful. Ulta Beauty is the largest U.S. beauty retailer and the premier beauty destination for cosmetics, fragrance, skin care products, hair care products and salon services. In 1990, the Company reinvented the beauty retail experience by offering a new way to shop for beauty — bringing together all things beauty, all in one place. Today, Ulta Beauty has grown to become the top national retailer offering the complete beauty experience.\u003c/p\u003e\n\n\u003cp\u003eUlta Beauty brings possibilities to life through the power of beauty each and every day in our stores and online with more than 25,000 products from approximately 500 well-established and emerging beauty brands across all categories and price points, including Ulta Beauty's own private label. Ulta Beauty also offers a full-service salon in every store featuring hair, skin, brow, and make-up services.\u003c/p\u003e\n\n\u003cp\u003eNo technology is perfect and Ulta Beauty believes that working with skilled security researchers across the globe is crucial in identifying potential vulnerabilities in any technology. We are excited for you to participate as a security researcher to help us identify potential vulnerabilities in our websites and applications. Good luck, and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings\u003c/h2\u003e\n\n\u003cp\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In the event of a downgrade, a reasonable explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority. However, final discretion remains with Ulta.\u003c/p\u003e","industryTagId":"9ed1ce49-a148-438f-92d3-0b8d70b6a8ae","targetsOverview":"\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Ulta Beauty not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you believe you've identified a vulnerability on a system outside the scope, please reach out to \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support\u003c/a\u003e before submitting.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eProgram Rules\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eBy participating in Ulta’s vulnerability disclosure program, you agree to be bound to the terms of this program brief. This program is not an offer of employment. We may modify or cancel this program at any time. \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eGuidelines\u003c/h3\u003e\n\n\u003cp\u003eAll researchers must read and agree to abide by the terms of this program brief. To encourage responsible disclosure, we will presume you are acting in good faith if we determine that your research and disclosure meets these guidelines:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eFollow this program brief, the Bugcrowd \u003ca href=\"https://www.bugcrowd.com/resources/essentials/standard-disclosure-terms/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eStandard Disclosure Terms\u003c/a\u003e, and any other relevant agreements. In case of inconsistency, this policy takes precedence.\u003c/li\u003e\n\u003cli\u003eComply with all applicable Federal, State, and local laws in connection with security research activities or other participation in this vulnerability disclosure program.\u003c/li\u003e\n\u003cli\u003eTest only in-scope systems and respect out-of-scope systems.\u003c/li\u003e\n\u003cli\u003eTest the targets listed above to detect a vulnerability for the sole purpose of providing Ulta information about such vulnerability.\u003c/li\u003e\n\u003cli\u003eCollect only the information necessary to demonstrate the vulnerability.\u003c/li\u003e\n\u003cli\u003eDo not exploit any vulnerability beyond the minimal amount of testing required to prove that the vulnerability exists or to identify an indicator related to that vulnerability.\u003c/li\u003e\n\u003cli\u003eDo not access, modify, or use data nonpublic data or data belonging to others, including customer information, employee personal information, or confidential or proprietary information of any party. If a vulnerability exposes such data, stop testing, submit a report immediately, and delete all copies of the information. \u003c/li\u003e\n\u003cli\u003eWhile the use of automated scanning tools is not prohibited, our security operations team routinely blocks broad and persistent scanning activity. You should limit the scope and frequency of any scanning to prevent this.\u003c/li\u003e\n\u003cli\u003ePayment processing is within the scope of this engagement however, please be aware that researchers will not be reimbursed for any purchases.\u003c/li\u003e\n\u003cli\u003ePromptly report discovered vulnerabilities.\u003c/li\u003e\n\u003cli\u003eUse the Bugcrowd report submission form to report vulnerability information to us.\u003c/li\u003e\n\u003cli\u003eUse Ulta’s Bugcrowd program for vulnerability-related communication. \u003c/li\u003e\n\u003cli\u003eMake every effort to avoid privacy violations, degradation of user experience, disruption to Ulta’s systems and operations, and destruction or manipulation of data. Do not delete, alter, share, retain, or destroy Ulta data, or render Ulta data inaccessible. \u003c/li\u003e\n\u003cli\u003eDo not engage in extortion, threats, or other tactics to elicit a response under duress. Ulta denies Safe Harbor for vulnerability disclosure conducted under such circumstances. \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eEligibility\u003c/h3\u003e\n\n\u003cp\u003eThe researcher and the vulnerability must be eligible according to this policy, including, but not limited to, the following requirements:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAll vulnerabilities must be new discoveries. Rewards will be provided only to the first researcher who submits a particular vulnerability. Identical issues across different products and environments will be considered duplicates.\u003c/li\u003e\n\u003cli\u003e\u003cp\u003eThe researcher must be at least 18 years of age. \u003c/p\u003e\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eA researcher must not be:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eA current or former employee of Ulta or an Ulta subsidiary, or a family member or household member of such an employee.\u003cbr\u003e\n\u003c/li\u003e\n\u003cli\u003eA contingent staff member, contractor or vendor employee currently working with Ulta.\u003c/li\u003e\n\u003cli\u003eThe author of or have any prior affiliation in the development or testing of the Ulta web property or application listed in the target section. \u003c/li\u003e\n\u003cli\u003eLocated in \u003ca href=\"https://www.bis.doc.gov/index.php/policy-guidance/country-guidance/sanctioned-destinations\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ea country currently on a United States sanctions list\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eReporting Requirements\u003c/h3\u003e\n\n\u003cp\u003eReports must contain specific, clearly articulated and actionable details regarding the vulnerability to qualify for a reward. Such details include, for example, a description of the vulnerability, its location (e.g. full URL), the potential impact, technical information needed to reproduce the vulnerability, any proof of concept code, and any other information you may believe is relevant or necessary for Ulta to identify and remedy the vulnerability. An example of the vulnerability report would include a detailed summary, including:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eType of vulnerability\u003c/li\u003e\n\u003cli\u003eIP Address or hostname\u003c/li\u003e\n\u003cli\u003eDescription of vulnerability\u003c/li\u003e\n\u003cli\u003eInstructions to replicate\u003c/li\u003e\n\u003cli\u003ePotential impact to system/site\u003c/li\u003e\n\u003cli\u003eRecommended remediation actions\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003eCredentials will not be provided for this engagement. However, researchers are able to create their own accounts if needed. If you would like to create an account, please sign up using your @bugcrowdninja email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003ePII Exposure\u003c/li\u003e\n\u003cli\u003eAreas of our application that expose build information or version numbers\u003c/li\u003e\n\u003cli\u003eSalon booking services\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut of Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eDenial of service (DoS and DDoS) attacks, brute force attacks, or other tests that impair access to or damage a system or data\u003c/li\u003e\n\u003cli\u003ePhysical testing, social engineering, or any other non-technical vulnerability testing\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003eNotwithstanding the program safe harbor, you are expected, as always, to comply with all applicable laws. Ulta reserves all of legal rights in the event of noncompliance.\u003c/p\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"3575850d-05e5-4a32-81f3-9991c8afe383","name":"SpaceNK Website","targets":[{"id":"1632aa81-c7d8-4c69-a6c5-a351dfb0e333","uri":"https://www.ulta.com","name":"Main Website","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"4173e19f-a5ad-4359-a1bc-2e026288d328","sortOrder":0},"sortOrder":0,"tags":[{"id":"076d29a6-dedd-43ec-ae8a-6c8ea571915b","name":"SQL","targetId":"1632aa81-c7d8-4c69-a6c5-a351dfb0e333"},{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"1632aa81-c7d8-4c69-a6c5-a351dfb0e333"},{"id":"3585ef4a-cd09-429b-ad25-5777064e59c5","name":"Moment.js","targetId":"1632aa81-c7d8-4c69-a6c5-a351dfb0e333"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"1632aa81-c7d8-4c69-a6c5-a351dfb0e333"},{"id":"a41318b7-d0b8-4b39-8250-dbbad194e770","name":"MongoDB","targetId":"1632aa81-c7d8-4c69-a6c5-a351dfb0e333"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"1632aa81-c7d8-4c69-a6c5-a351dfb0e333"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"1632aa81-c7d8-4c69-a6c5-a351dfb0e333"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"1632aa81-c7d8-4c69-a6c5-a351dfb0e333"}],"recentChangeFlags":null},{"id":"05b62e0f-6444-42f5-9806-c6ae34f6e987","uri":"https://play.google.com/store/apps/details?id=com.ulta\u0026hl=en_US\u0026gl=US","name":"Mobile Application - Android","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"dd8d5f9c-a017-4ab2-9f88-8b937ccefb62","sortOrder":0},"sortOrder":0,"tags":[{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"05b62e0f-6444-42f5-9806-c6ae34f6e987"}],"recentChangeFlags":null},{"id":"30b80df2-779f-4f74-936d-27f61cbcc88b","uri":"https://apps.apple.com/us/app/ulta-beauty-makeup-skincare/id561930308","name":"Mobile Application - iOS","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"f7e7211f-6592-423c-b185-fa6934d6fa40","sortOrder":0},"sortOrder":0,"tags":[{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"30b80df2-779f-4f74-936d-27f61cbcc88b"}],"recentChangeFlags":null},{"id":"94e40fb2-ec4b-4595-b128-b90acad2bc74","uri":"https://www.glamst.com","name":"Glam Street","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d2ed0335-7d1c-42d2-81e7-59f068186c33","sortOrder":3},"sortOrder":3,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"94e40fb2-ec4b-4595-b128-b90acad2bc74"}],"recentChangeFlags":null},{"id":"a823460c-73fa-4c5a-8161-dd993419c482","uri":"https://www.ultainc.com","name":"Ulta Inc","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"63bdeba7-a43c-4141-826f-b2ce9d706e08","sortOrder":4},"sortOrder":4,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"a823460c-73fa-4c5a-8161-dd993419c482"}],"recentChangeFlags":null},{"id":"7cb00d2c-cabc-4015-abb0-085b34b1fd9f","uri":"https://www.ultatraining.com","name":"Ulta Training","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"e9ab4f7d-2fdf-4af1-b8b4-0b4179a1f717","sortOrder":5},"sortOrder":5,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"7cb00d2c-cabc-4015-abb0-085b34b1fd9f"}],"recentChangeFlags":null},{"id":"e4a9fa38-cb73-4f29-89b4-c6be7660e9ae","uri":"https://www.spacenk.com","name":"SpaceNK Website","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"3b5c3094-945f-463c-a5bf-38eea14bc3b1","sortOrder":6},"sortOrder":6,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"e4a9fa38-cb73-4f29-89b4-c6be7660e9ae"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"261fb647-f15f-4f6a-8d97-4856d8ad6907","code":"ultabeauty-vdp","state":"in_progress","endsAt":null,"bountyId":"47b1c2d6-fdf0-4b6e-8441-72490d26f707","startsAt":"2023-08-31T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Retail","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/95da/c11e/81f5777d/97c5416de3eb8415d712a85906140dd5_1583529391633.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2023-08-31T18:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/ultabeauty-vdp","changelogs":"/engagements/ultabeauty-vdp/changelog","submissions":null,"announcements":"/engagements/ultabeauty-vdp/announcements","hallOfFame":"/engagements/ultabeauty-vdp/hall_of_fames","crowdstream":"/engagements/ultabeauty-vdp/crowdstream"},"announcementsCount":0,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/ultabeauty-vdp/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=ultabeauty-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/ultabeauty-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/ultabeauty-vdp/changelog","publishedAt":"2025-10-23T17:14:59.467Z","engagementChangelogUrl":"/engagements/ultabeauty-vdp/changelog/99b04282-0f12-4f72-81a8-fab3bdfd90d7","createUserFeedbacksUrl":"/engagements/ultabeauty-vdp/feedbacks","engagementCrowdstreamUrl":"/engagements/ultabeauty-vdp/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}