{"id":"762b2474-e004-41d0-b720-c050b4e16705","engagementId":"587bcf67-4ba8-44d3-bfd9-831a7b7a7a93","data":{"brief":{"id":"0959dda4-3989-4f21-998f-b8f48e7a350d","name":"Vinted Bug Bounty","tagline":"Vinted is a leading peer-to-peer re-commerce platform dedicated to making second-hand fashion and lifestyle items the first choice across Europe.","description":"\u003cp\u003eVinted's mission is to make second-hand the first choice worldwide by building a sustainable circular model and taking it global. We are an online marketplace where members buy and sell pre-loved items directly with each other, and they trust us with their identity, their money and their home address while they do it.\u003c/p\u003e\n\n\u003cp\u003eWe ran a bug bounty program previously and it worked: 594 submissions, 155 of them valid, a lot of issues fixed before anyone outside noticed. We have moved to Bugcrowd to reach a wider crowd. We have done our best to clean up what we know about — now we would like your help finding what we missed.\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/p\u003e","industryTagId":"1bf3970a-395b-4456-b261-d04dab482af2","targetsOverview":"\u003ch2\u003eScope and Rewards\u003c/h2\u003e\n\n\u003cp\u003eTesting is only authorised on the targets listed as in scope. Any domain/property of Vinted not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to Vinted, you can report it to us. However, be aware that it might be ineligible for rewards or points-based compensation.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eEngagement Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWe do not accept reports that contain low-effort or AI-generated content. Submissions must demonstrate original analysis, clear understanding of the issue, and actionable detail. Reports lacking meaningful human input will be rejected\u003c/li\u003e\n\u003cli\u003eResearchers must throttle all testing activity to avoid degrading service availability, triggering automated defenses, or negatively impacting other users. Excessive request rates, high-volume scanning, denial-of-service techniques, or other disruptive testing methods are prohibited\u003c/li\u003e\n\u003cli\u003ePotential post-exploitation scenarios: If you believe you've identified a vulnerability that may lead to post-exploitation activity including modification or destruction of data please stop testing and submit your finding. We will work with you to evaluate the vulnerability and award you accordingly for the final impact and severity\u003c/li\u003e\n\u003cli\u003eYou are testing on production. Behavior that compromises the stability and integrity of the target(s) is out of scope\n\n\u003cul\u003e\n\u003cli\u003eFor example, do not target other users' data (use one of your other sets of credentials), delete/remove/edit parts of the site, engage any sort of DoS attack, and/or compromise any target's ability to function for other users. If you believe that you have found a vulnerability of this nature, please stop further testing and report it\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eReport Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eVulnerabilities discovered on multiple paths, endpoints, parameters will be treated as duplicates. This includes findings across different environments (e.g., development, staging, production) unless the impact or exploitation method is materially different. Please submit only one report\u003c/li\u003e\n\u003cli\u003eReports must contain the role used for testing, a clear explanation of the issue and the security impact along with detailed steps to reproduce it. If the issue cannot be reliably reproduced based on your report, it may be considered ineligible for a reward\u003c/li\u003e\n\u003cli\u003eReports based only on automated tool/scanner results or which describe theoretical attack vectors without proof of exploitability will not be accepted\u003c/li\u003e\n\u003cli\u003eDo not submit more than one vulnerability per report. In cases where demonstrating impact requires chaining multiple vulnerabilities together, those can be included in the same report as long as the linkage is clearly explained\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003ePII \u0026amp; Customer Data Handling\u003c/h2\u003e\n\n\u003cp\u003eReports, comments, and attachments must not contain customer PII or customer information of any kind. Where evidence genuinely requires the inclusion of such data to demonstrate a vulnerability, engagement owners will provide a private, secure channel for the hand-over.Handle Data Like It’s Yours\u003c/p\u003e\n\n\u003cp\u003eWe operate under strict data privacy regulations, including GDPR. We expect researchers to treat all data with the highest level of care. To maintain compliance and protect our members, please adhere to the following:\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eAccidental Access\u003c/strong\u003e: If you inadvertently reach another person's data, stop testing immediately. Capture only the absolute minimum evidence required to support your claim. Do not pivot to other records, do not enumerate data, and report the finding immediately.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eMandatory Deletion\u003c/strong\u003e: You are required to delete any member data obtained during your testing. Confirmed deletion is a condition of reward eligibility.\u003c/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eStorage \u0026amp; Buckets:\u003c/strong\u003e Do not download the contents of publicly readable S3 buckets or similar storage mechanisms. If a bucket appears to contain sensitive information, do not attempt to access the contents; instead, log a ticket providing the bucket name and/or folder structure as sufficient evidence of the misconfiguration.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess\u003c/h2\u003e\n\n\u003cp\u003eAll targets within the scope are publicly accessible.\u003c/p\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003eTo gain access to the applications, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cp\u003eTo support your testing, we’ve highlighted several key areas of interest. While we ask that you report any efforts related to these areas, please note that testing is not limited to them. Submissions outside of these focus areas are equally welcomed and appreciated.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eBusiness-Logic \u0026amp; Financial Impact\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eWe are equally interested in business-logic flaws. This includes any issue that causes reputational damage to a buyer or seller, or enables fraud against our members or Vinted itself.\u003c/li\u003e\n\u003cli\u003ePlease note: Depending on the report, these findings may be treated at a higher severity or payout than the raw CVSS score suggests. If your finding does not fit a \"textbook\" vulnerability class but clearly results in financial loss, please submit it.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eN-day/Third party 0-day Policy\u003c/h2\u003e\n\n\u003cp\u003eWhen N-Day bugs are released to the public and can be exploited within our target(s), please let us know immediately. Each report will be reviewed on a case by case basis.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eExcluded Submission Types\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eGeneral\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eIssues already known to us from our own testing (flagged as duplicate)\u003c/li\u003e\n\u003cli\u003eTheoretical issues with no realistic exploit scenario, or requiring complex end-user interaction\u003c/li\u003e\n\u003cli\u003eSpam, social engineering, physical intrusion\u003c/li\u003e\n\u003cli\u003eDoS / DDoS / brute force\u003c/li\u003e\n\u003cli\u003eAttacks requiring physical device access, MITM, or an already-compromised account\u003c/li\u003e\n\u003cli\u003eZero-days in in-scope assets within 14 days of a public patch or mitigation may be reported, but are usually not eligible for a bounty\u003c/li\u003e\n\u003cli\u003e\"This software is out of date\" without a PoC\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eApplication\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAPI key disclosure without proven business impact\u003c/li\u003e\n\u003cli\u003eDisclosed or misconfigured Google Maps API keys\u003c/li\u003e\n\u003cli\u003ePre-auth account takeover / OAuth squatting\u003c/li\u003e\n\u003cli\u003eSelf-XSS not usable against another member\u003c/li\u003e\n\u003cli\u003eVerbose errors, files or directory listings disclosing nothing sensitive\u003c/li\u003e\n\u003cli\u003eCORS misconfiguration on non-sensitive endpoints\u003c/li\u003e\n\u003cli\u003eMissing cookie flags; missing security headers\u003c/li\u003e\n\u003cli\u003eCSRF with no or low impact\u003c/li\u003e\n\u003cli\u003eautocomplete attribute present on web forms\u003c/li\u003e\n\u003cli\u003eReverse tabnabbing; same-site scripting; homograph attacks\u003c/li\u003e\n\u003cli\u003eRate-limit bypass or absence of rate limits\u003c/li\u003e\n\u003cli\u003ePassword-policy best-practice violations\u003c/li\u003e\n\u003cli\u003eClickjacking without proven impact or requiring unrealistic interaction\u003c/li\u003e\n\u003cli\u003eCSV injection\u003c/li\u003e\n\u003cli\u003eOutput of automated scanners\u003c/li\u003e\n\u003cli\u003eSessions not invalidated on logout or 2FA enablement\u003c/li\u003e\n\u003cli\u003eTokens leaked to third parties\u003c/li\u003e\n\u003cli\u003eEmail spoofing, SPF, DMARC, DKIM\u003c/li\u003e\n\u003cli\u003eUsername / email enumeration; email bombing\u003c/li\u003e\n\u003cli\u003eHTTP request smuggling without proven impact\u003c/li\u003e\n\u003cli\u003eHost header injection without proven impact\u003c/li\u003e\n\u003cli\u003eXMLRPC enabled; banner grabbing and version disclosure\u003c/li\u003e\n\u003cli\u003eFile metadata not stripped\u003c/li\u003e\n\u003cli\u003eSubdomain takeover without actually taking over the subdomain\u003c/li\u003e\n\u003cli\u003eArbitrary file upload without proof the file exists on the server\u003c/li\u003e\n\u003cli\u003eBlind SSRF without proven business impact (pingbacks are not sufficient)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eMobile\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eShared links leaked via the system clipboard\u003c/li\u003e\n\u003cli\u003eURIs visible to a malicious app with URI-viewing permission\u003c/li\u003e\n\u003cli\u003eAbsence of certificate pinning or SSL pinning\u003c/li\u003e\n\u003cli\u003eSensitive data in URLs or request bodies protected by TLS\u003c/li\u003e\n\u003cli\u003eLack of obfuscation or anti-debugging controls\u003c/li\u003e\n\u003cli\u003ePath disclosure in the binary\u003c/li\u003e\n\u003cli\u003eLack of jailbreak / root detection; runtime exploits requiring a jailbroken device\u003c/li\u003e\n\u003cli\u003eCrashes from malformed URL schemes\u003c/li\u003e\n\u003cli\u003eSnapshot / pasteboard leakage\u003c/li\u003e\n\u003cli\u003eAPI key leakage used for non-sensitive actions\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cstrong\u003eAWS\u003c/strong\u003e\u003c/p\u003e\n\n\u003cp\u003ePublicly readable S3 buckets. Several of ours are public by design as caches for the website and other public resources - unless the contents clearly should not be public (personal data, confidential files). If unsure, log a ticket with examples of the folder structure. Do not download the data.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eDo not touch real members\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eTest only against accounts, listings and orders you own end to end. Need a buyer and a seller? Create both.\u003c/li\u003e\n\u003cli\u003eDo not interact with real members' listings, messages, reviews or orders. Not a favourite, not a follow.\u003c/li\u003e\n\u003cli\u003eDo not buy from or sell to a real member. If a genuine member messages you, explain you are testing and stop.\u003c/li\u003e\n\u003cli\u003eTest listings must be obviously fake, work-appropriate and cheaply priced. Please do not list your flatmate's cat, however available they may be.\u003c/li\u003e\n\u003cli\u003eNo bulk creation of listings, accounts or transactions. Find a gap that allows unlimited creation? Stop at the proof and tell us.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eOut-of-Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eP5 vulnerabilities\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvailability/volumetric testing e.g.:\n\n\u003cul\u003e\n\u003cli\u003eDoS/DDoS/Network DoS\u003c/li\u003e\n\u003cli\u003eRate limiting bypass attempts\u003c/li\u003e\n\u003cli\u003eEmail bombing flooding\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eResponse Times to Submissions\u003c/h2\u003e\n\n\u003cp\u003eWe are committed to reviewing every submission fairly and thoroughly. To manage expectations around feedback:\u003cbr\u003e\nPlease allow sufficient time for feedback on your submission. Our programs span multiple entities, teams and time zones, and each finding is validated with the relevant internal teams before we respond. Feedback on more complex findings will take a lot longer and will be attended to eventually. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eData Handling \u0026amp; Privacy\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eHandle data like it's yours: If you can reach another person's data: stop, capture the minimum evidence needed, do not pivot, and do not enumerate. Report the issue immediately.\u003c/li\u003e\n\u003cli\u003eData Deletion: You are required to delete any member data obtained during your testing. Confirmed deletion is a condition of reward eligibility. As we are a European company, we are subject to GDPR regulations and must maintain strict data compliance.\u003c/li\u003e\n\u003cli\u003eS3 Buckets: Do not download the contents of publicly readable S3 buckets. If a bucket appears to contain sensitive information, log a ticket with the folder structure as your evidence instead.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/li\u003e\n\u003cli\u003eAuthorised in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our \u003ca href=\"https://www.bugcrowd.com/resources/hacker-resources/standard-disclosure-terms/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eTerms \u0026amp; Conditions\u003c/a\u003e that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via our \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/login\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eFreshdesk Portal \u003c/a\u003ebefore going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"951a4faa-18ee-42cb-9382-6a2aa1e6c7bf","name":"Primary Target Group","targets":[{"id":"3ec2e73b-e8e1-468a-b484-5bac206731ff","uri":"https://www.vinted.com","name":"www.vinted.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"69a43ab1-3eec-45fb-ab7f-4cb3c165d1e6","sortOrder":0},"sortOrder":0,"tags":[{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"3ec2e73b-e8e1-468a-b484-5bac206731ff"},{"id":"624f911d-7e8c-4d56-b523-e7416c1cc319","name":"NextJS","targetId":"3ec2e73b-e8e1-468a-b484-5bac206731ff"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"3ec2e73b-e8e1-468a-b484-5bac206731ff"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"3ec2e73b-e8e1-468a-b484-5bac206731ff"}],"recentChangeFlags":null},{"id":"81fd6071-83dc-40d6-89ef-41b09ed9ca08","uri":"https://www.vinted.net","name":"www.vinted.net","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d91f0df8-5148-4b48-a144-5c9bce9937b2","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null},{"id":"1e068248-1be4-4d73-87e2-aec2970ee618","uri":"https://www.vintedgo.com","name":"www.vintedgo.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b8389b3f-bd7d-4c2f-9cd4-714b89b5480e","sortOrder":2},"sortOrder":2,"tags":[{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"1e068248-1be4-4d73-87e2-aec2970ee618"},{"id":"624f911d-7e8c-4d56-b523-e7416c1cc319","name":"NextJS","targetId":"1e068248-1be4-4d73-87e2-aec2970ee618"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"1e068248-1be4-4d73-87e2-aec2970ee618"}],"recentChangeFlags":null},{"id":"2ac62dd9-7ae8-418a-81df-33d755870036","uri":"https://apps.apple.com/us/app/vinted-pre-loved-marketplace/id632064380","name":"Vinted iOS application","category":"ios","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"b8f5f5a9-fb39-42f3-97b3-94e3f052859c","sortOrder":3},"sortOrder":3,"tags":[{"id":"e251f4f0-1204-4c8a-9e12-dba8fdaadf48","name":"iOS","targetId":"2ac62dd9-7ae8-418a-81df-33d755870036"}],"recentChangeFlags":null},{"id":"94ba2165-fdfd-4485-90a9-29a59d1819b1","uri":"https://play.google.com/store/apps/details?id=fr.vinted","name":"Vinted Android application","category":"android","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"497f3ca4-fdcf-41d5-9aa9-6809f2efe929","sortOrder":4},"sortOrder":4,"tags":[{"id":"ee1461dd-e5fd-4e9d-8c95-0344ba08bdc2","name":"Android","targetId":"94ba2165-fdfd-4485-90a9-29a59d1819b1"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"3baeb114-bf13-4260-8874-30011cad7903","p1MaxCents":400000,"p1MinCents":200000,"p2MaxCents":150000,"p2MinCents":80000,"p3MaxCents":50000,"p3MinCents":20000,"p4MaxCents":15000,"p4MinCents":7500,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":2000,"max":4000},"2":{"min":800,"max":1500},"3":{"min":200,"max":500},"4":{"min":75,"max":150},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"6ea60fab-02dc-4b0e-b438-d073adeaf80c","name":"Secondary Target Group","targets":[{"id":"69c06805-5474-49b3-b71e-9601b3d59c02","uri":"https://sandbox.vintedgo.com","name":"Vinted Go Sandbox","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"81f46b7a-b724-4856-bd89-117ee7744b47","sortOrder":0},"sortOrder":0,"tags":[{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"69c06805-5474-49b3-b71e-9601b3d59c02"}],"recentChangeFlags":null},{"id":"a0fa8ad4-fff1-4342-a0c2-f149b58f93d4","uri":"https://sandbox.vinted.com","name":"Vinted Sandbox","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"440fc86a-a130-44f8-af3c-87e9b9ef6eb5","sortOrder":1},"sortOrder":1,"tags":null,"recentChangeFlags":null},{"id":"62081942-d45d-4c39-beff-e19d42976bd0","uri":"https://test-escalations.vintedgo.com","name":"Vinted Go Escalations test","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"d206b4d4-fba1-4525-a15b-0e784f63865f","sortOrder":2},"sortOrder":2,"tags":[{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"62081942-d45d-4c39-beff-e19d42976bd0"},{"id":"3585ef4a-cd09-429b-ad25-5777064e59c5","name":"Moment.js","targetId":"62081942-d45d-4c39-beff-e19d42976bd0"},{"id":"eaa69542-87cd-413a-9b74-3e75f9fb01e4","name":"Angular","targetId":"62081942-d45d-4c39-beff-e19d42976bd0"}],"recentChangeFlags":null},{"id":"c4c52cdd-ddb1-4c2d-860b-cf7f2187df40","uri":"https://badger.it.vinted.com","name":"Encryption Service","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"67b3d2cf-a909-4847-b2be-347b8fe2bfb8","sortOrder":3},"sortOrder":3,"tags":null,"recentChangeFlags":null},{"id":"41e819d8-2a50-4310-b212-b0c4fcb51725","uri":"https://careers.vinted.com","name":"Vinted Careers","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"dade7c3d-ef0e-41b1-8334-61e2d3a160cc","sortOrder":4},"sortOrder":4,"tags":[{"id":"624f911d-7e8c-4d56-b523-e7416c1cc319","name":"NextJS","targetId":"41e819d8-2a50-4310-b212-b0c4fcb51725"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"41e819d8-2a50-4310-b212-b0c4fcb51725"}],"recentChangeFlags":null},{"id":"93dc3ef8-89a4-46fe-912c-b4c8ca98ae3a","uri":"https://company.vinted.com","name":"Company Vinted","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"ef422b26-6ff2-4749-a742-6a7d42e2dbeb","sortOrder":5},"sortOrder":5,"tags":[{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"93dc3ef8-89a4-46fe-912c-b4c8ca98ae3a"},{"id":"624f911d-7e8c-4d56-b523-e7416c1cc319","name":"NextJS","targetId":"93dc3ef8-89a4-46fe-912c-b4c8ca98ae3a"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"93dc3ef8-89a4-46fe-912c-b4c8ca98ae3a"}],"recentChangeFlags":null},{"id":"7e51daac-fc75-4e27-8b77-e62dad1d32f1","uri":"https://news.vinted.com","name":"News Vinted","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"6ccdc1f6-0474-4328-ac93-55ff2cfd9d9b","sortOrder":6},"sortOrder":6,"tags":null,"recentChangeFlags":null}],"inScope":true,"sortOrder":2,"description":null,"rewardRange":{"id":"60c38b03-01e7-4357-98ef-8aa40410a0e1","p1MaxCents":80000,"p1MinCents":50000,"p2MaxCents":40000,"p2MinCents":25000,"p3MaxCents":15000,"p3MinCents":10000,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":null,"rewardRangeData":{"1":{"min":500,"max":800},"2":{"min":250,"max":400},"3":{"min":100,"max":150},"4":{"min":null,"max":null},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"587bcf67-4ba8-44d3-bfd9-831a7b7a7a93","code":"vinted-uab-mbb","state":"in_progress","endsAt":null,"bountyId":"0169eff4-55ce-46e1-af8a-86a8add4b962","startsAt":"2026-08-11T18:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"eCommerce","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/0753/e399/312b36be/befc2765097855046d54e6f38c26d778_vinted_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2026-08-11T18:01:00.237Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/vinted-uab-mbb","changelogs":"/engagements/vinted-uab-mbb/changelog","submissions":null,"announcements":"/engagements/vinted-uab-mbb/announcements","hallOfFame":"/engagements/vinted-uab-mbb/hall_of_fames","crowdstream":"/engagements/vinted-uab-mbb/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/vinted-uab-mbb/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":"updated","userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=vinted-uab-mbb\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/vinted-uab-mbb/engagement_subscribers","engagementChangelogsUrl":"/engagements/vinted-uab-mbb/changelog","publishedAt":"2026-09-30T13:32:57.630Z","engagementChangelogUrl":"/engagements/vinted-uab-mbb/changelog/762b2474-e004-41d0-b720-c050b4e16705","createUserFeedbacksUrl":"/engagements/vinted-uab-mbb/feedbacks","engagementCrowdstreamUrl":"/engagements/vinted-uab-mbb/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}