{"id":"a6464e6a-c230-4dba-99b1-dd54f2eb51be","engagementId":"c6c033ac-3e4d-44df-86d8-51e96390a0fd","data":{"brief":{"id":"f498a157-9a80-4d37-b269-399d9edab666","name":"Unilever Vulnerability Disclosure Program","tagline":"At Unilever we meet everyday needs for nutrition, hygiene and personal care with brands that help people feel good, look good and get more out of life.","description":"\u003cp\u003eNo technology is perfect and Unilever believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher in order to identify weaknesses in our web applications. If you believe you've found a security issue, we encourage you to notify us. We welcome working with you to resolve the issue promptly.\u003c/p\u003e\n\n\u003ch2\u003eRatings:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e","industryTagId":null,"targetsOverview":"\u003cp\u003eTesting is only authorized on the targets listed as In-Scope. \u003cem\u003eAny domain/property of Unilever not listed in the targets section is out of scope. This includes any/all subdomains not listed above.\u003c/em\u003e If you believe you've identified a vulnerability on a system outside the scope, please reach out to support@bugcrowd.com before submitting.\u003c/p\u003e\n\n\u003cp\u003eUnilever is starting this program with their primary public facing web application on \u003ca href=\"https://unilever.com\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eunilever.com\u003c/a\u003e.  As the program progresses more targets will be added to the program.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eScanning Activity\u003c/h3\u003e\n\n\u003cp\u003e\u003cstrong\u003ePlease do not use automated vulnerability scanners on this program. Custom scripts and fuzzing tools are permitted, but if using them, please keep your traffic to six requests per second or less. Additionally, it’s worth noting that the client already runs automated scans from Acunetix, Zap, Nessus, et al., against the in-scope targets – so using these tools is likely of minimal utility to researchers. As such, please avoid using them unless for targeted, specific testing, and then only at less than six requests per second.\u003c/strong\u003e\u003c/p\u003e\n\n\u003ch2\u003eExclusions\u003c/h2\u003e\n\n\u003ch3\u003eNon-qualifying vulnerabilities / Known Issues\u003c/h3\u003e\n\n\u003cp\u003eWhen reporting vulnerabilities, please consider (1) attack scenario/exploitability, and (2) security impact of the bug. The following issues are considered out of scope:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eClickjacking on pages with no sensitive actions\u003c/li\u003e\n\u003cli\u003eAttacks requiring MITM or physical access to a user's device.\u003c/li\u003e\n\u003cli\u003ePreviously known vulnerable libraries without a working Proof of Concept.\u003c/li\u003e\n\u003cli\u003eComma Separated Values (CSV) injection without demonstrating a vulnerability.\u003c/li\u003e\n\u003cli\u003eMissing best practices in SSL/TLS configuration.\u003c/li\u003e\n\u003cli\u003eAny activity that could lead to the disruption of our service (DoS).\u003c/li\u003e\n\u003cli\u003eContent spoofing and text injection issues without showing an attack vector/without being able to modify HTML/CSS\u003c/li\u003e\n\u003cli\u003eRate limiting or brute force issues on non-authentication endpoints\u003c/li\u003e\n\u003cli\u003eMissing best practices in Content Security Policy.\u003c/li\u003e\n\u003cli\u003eMissing HttpOnly or Secure flags on cookies\u003c/li\u003e\n\u003cli\u003eMissing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)\u003c/li\u003e\n\u003cli\u003eVulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]\u003c/li\u003e\n\u003cli\u003eSoftware version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors).\u003c/li\u003e\n\u003cli\u003ePublic Zero-day vulnerabilities that have had an official patch for less than 1 month will be awarded on a case by case basis.\u003c/li\u003e\n\u003cli\u003eTab nabbing\u003c/li\u003e\n\u003cli\u003eOpen redirect - unless an additional security implication can be demonstrated\u003c/li\u003e\n\u003cli\u003eSelf XSS\u003c/li\u003e\n\u003cli\u003ePromo code abuse (e.g. ordering multiple times using the same promo code)\u003c/li\u003e\n\u003cli\u003eAbuse of our promotional offers and referral codes\u003c/li\u003e\n\u003cli\u003ePromo code enumeration, abuse of our promotional offers and referral codes.\u003c/li\u003e\n\u003cli\u003eAble to retrieve user's public information.\u003c/li\u003e\n\u003cli\u003eUsername / email enumeration\u003c/li\u003e\n\u003cli\u003eBugs in 3rd party authentications (attacks specifically against our implementation are fine)\u003c/li\u003e\n\u003cli\u003eResults from automated tools without any manual confirmation\u003c/li\u003e\n\u003cli\u003eBugs affecting 3rd party sites that consume data from Social Club\u003c/li\u003e\n\u003cli\u003eAny similar action that interferes with a user's privacy, security or experience\u003c/li\u003e\n\u003cli\u003eClear Text / HTTP Basic Authentication\u003c/li\u003e\n\u003cli\u003eInternal Path disclosure\u003c/li\u003e\n\u003cli\u003eBlind XSS, Blind SSRF with no actual exploitation \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":false,"additionalInformation":""},"scope":[{"id":"2fc9a9a8-5aa6-4a67-8843-08bbaa2954b2","name":"███████████████████████","targets":[{"id":"87dd021a-2ffe-4db1-8dad-3494e8e72f9b","uri":null,"name":"███████████████████████████████","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"693be8b8-41de-40f6-878d-a4fa4cd368eb","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"87dd021a-2ffe-4db1-8dad-3494e8e72f9b"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":null,"descriptionHtml":null,"rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"c6c033ac-3e4d-44df-86d8-51e96390a0fd","code":"unilever-vdp","state":"in_progress_paused","endsAt":null,"bountyId":"649cf5de-ead9-47bd-994e-365ab5ec2b5a","startsAt":"2020-03-12T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":null,"methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/bd10/5474/f270493b/6184621533dfe4e34b96d574dd2630d7_unilever.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":false,"participation":"open","rewardAllocation":"no_reward","engagementTypeDetail":{"iconVariant":"vdp","productLabel":"Vulnerability Disclosure","timeboxed":false},"pausedReason":"Pausing ","lastTransitionAt":"2026-09-08T15:23:44.261Z","cancellationReason":null,"statusLabel":"In progress paused","routesPaths":{"brief":"/engagements/unilever-vdp","changelogs":"/engagements/unilever-vdp/changelog","submissions":null,"announcements":"/engagements/unilever-vdp/announcements","hallOfFame":"/engagements/unilever-vdp/hall_of_fames","crowdstream":"/engagements/unilever-vdp/crowdstream"},"announcementsCount":31,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":null,"methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=unilever-vdp\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/unilever-vdp/engagement_subscribers","engagementChangelogsUrl":"/engagements/unilever-vdp/changelog","publishedAt":"2026-09-08T15:23:44.295Z","engagementChangelogUrl":"/engagements/unilever-vdp/changelog/a6464e6a-c230-4dba-99b1-dd54f2eb51be","createUserFeedbacksUrl":"/engagements/unilever-vdp/feedbacks","engagementCrowdstreamUrl":"/engagements/unilever-vdp/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}