{"id":"6bc3d4da-d19f-4458-8135-ad3a020ac71e","engagementId":"d71e802d-61d5-4bf5-bacb-24b0fd3d7cd7","data":{"brief":{"id":"961ed851-8aaa-4bc5-aaaf-850fe7b48f4f","name":"Volkswagen ","tagline":"We are #ShapingMobility – for generations to come.","description":"\u003cp\u003eVolkswagen invites you to test and help secure our primary publicly facing assets - focusing on our primary German website. We appreciate your efforts and hard work in making the internet (and Volkswagen) more secure, and look forward to working with the researcher community to create a meaningful and successful bug bounty program. Good luck and happy hunting!\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards:\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this program will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003cp\u003ePlease be aware that we have some quality assurance and test systems within our scope, as well as some showrooms / click-dummies. Most of the systems - but not all - have something like \"qa\" \"q\", \"test\", \"staging\", \"dev\", \"pre\" in their name.\u003cbr\u003e\nAs those stages(i.e. test-\u0026gt;qa-\u0026gt;prod) share the same codebase and are used for staged deployment of new releases, we will only reward the highest valued system from the first report we get regarding a destinct bug.\u003cbr\u003e\nPlease beware that we might lower the bounty for non prod systems according to their impact when only dummy data is affected and no further relevance (e.g. RCE, cookie stealing from other domains, ...) can be seen. We apologize for not being able to clearly mark those systems and promise rewards with respect to your work. Please make sure if you found a bug to try to reproduce this on prod to get the most value out of your bounty. Also make sure to provide neccessary evidence (e.g. screenshots) in case a system goes down during triage.\u003c/p\u003e","industryTagId":"84de63c9-6091-4b30-a36e-d55632cb0f0b","targetsOverview":"\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as In-Scope. Any domain/property of Volkwagen not listed in the targets section is out of scope. This includes any/all subdomains not listed above.  IF you happen to identify a security vulnerability on a target that is not in-scope, but that demonstrably belongs to Volkswagen, it may be reported \u003ca href=\"https://www.volkswagen.de/de/mehr/rechtliches/kontakt-cyber-security.html\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e. However, do be aware that is ineligible for rewards or points-based compensation\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eCredentials:\u003c/h3\u003e\n\n\u003cp\u003eNo credentials will be provided for this program. However, if any application that is found allows for account creation that would be considered in scope. If any accounts are able to be created, please use your @bugcrowdninja.com email address.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eScanning Activity\u003c/h3\u003e\n\n\u003cp\u003e\u003cstrong\u003ePlease do not use automated vulnerability scanners on this program. Custom scripts and fuzzing tools are permitted, but if using them, please keep your traffic to six requests per second or less. Additionally, it’s worth noting that the client already runs automated scans from Nessus et al., against the in-scope targets – so using these tools is likely of minimal utility to researchers. As such, please avoid using them unless for targeted, specific testing, and then only at less than six requests per second.\u003c/strong\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch3\u003eThe following finding types are out of scope:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eSelf XSS\u003c/li\u003e\n\u003cli\u003eEmail spoofing (including SPF, DKIM, DMARC, From: spoofing, and visually similar, and related issues)\u003c/li\u003e\n\u003cli\u003eCSRF issues that don't impact the integrity of an account (e.g. log in or out, contact forms and other publicly accessible forms)\u003c/li\u003e\n\u003cli\u003eLack of rate limiting\u003c/li\u003e\n\u003cli\u003eDenial of Service attacks\u003c/li\u003e\n\u003cli\u003eIssues only exploitable on user devices with old versions of operating systems or browsers\u003c/li\u003e\n\u003cli\u003eRecent unpatched CVEs in third party products/libraries\u003c/li\u003e\n\u003cli\u003eCVEs without security impact in third party products/libraries\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eThe following finding types are currently not eligible for rewards (P5), except if a concrete impact is demonstrated:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eInternal IP address disclosure\u003c/li\u003e\n\u003cli\u003eVulnerabilities of third party libraries without showing specific impact (e.g. CVE with no exploit)\u003c/li\u003e\n\u003cli\u003eInformation leaks without direct security impact (e.g. detailed server configuration, metrics/health endpoints, debug pages, descriptive error messages, stack traces, application or server errors, path disclosure)\u003c/li\u003e\n\u003cli\u003eClickjacking and issues only exploitable through clickjacking\u003c/li\u003e\n\u003cli\u003eMissing security best practices (e.g. missing CORS or Cache-Control header or Secure and HTTPOnly cookie flags without impact)\u003c/li\u003e\n\u003cli\u003eHTTPS mixed content scripts\u003c/li\u003e\n\u003cli\u003e3rd party content that is hosted on our site, but is controlled by the third party and only impacts the third party, for example broken social media links of car dealerships in the dealer search\u003c/li\u003e\n\u003cli\u003eUse of expired / self-signed Cryptographic Key (or Certificate)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch3\u003eCases for dangling IPs will be classified as follows:\u003c/h3\u003e\n\n\u003cul\u003e\n\u003cli\u003eIf the researcher was able to claim the IP, or the IP is still available at time of report, the case will be treated like a subdomain takeover\u003c/li\u003e\n\u003cli\u003eIf the IP was already reassigned to a third party, and it can be demonstrated that the third party is malicious, the case will be treated as a P4 with the \"Indicator of Compromise\" VRT\u003c/li\u003e\n\u003cli\u003eIf the IP was already reassigned to a third party that is not malicious, the case will be treated as P5\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e* These lists may not be exhaustive\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor:\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via support@bugcrowd.com before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"bba33b19-6351-4d5b-9df9-58747305cac4","name":"In Scope Targets","targets":[{"id":"f6318818-e213-4bfa-ba29-a464bb0a9051","uri":"","name":"*.volkswagen.de","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"d6841f24-eae4-4a96-8726-6a67ef930604","sortOrder":0},"sortOrder":0,"tags":[{"id":"1892c58d-2dbd-4b0d-96ee-1d2322fd1711","name":"Java","targetId":"f6318818-e213-4bfa-ba29-a464bb0a9051"},{"id":"187a0132-af2c-45e1-b4af-77ac6117b9dc","name":"Adobe Experience Manager","targetId":"f6318818-e213-4bfa-ba29-a464bb0a9051"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"f6318818-e213-4bfa-ba29-a464bb0a9051"},{"id":"45e28558-ada7-4f38-b087-fb0e6ac31e0d","name":"AWS","targetId":"f6318818-e213-4bfa-ba29-a464bb0a9051"},{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"f6318818-e213-4bfa-ba29-a464bb0a9051"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"f6318818-e213-4bfa-ba29-a464bb0a9051"},{"id":"ef82adfb-fd5b-439b-a090-ed44823bf259","name":"Azure","targetId":"f6318818-e213-4bfa-ba29-a464bb0a9051"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"b406db1d-2bcf-452b-aeab-51f79047bc0d","p1MaxCents":250000,"p1MinCents":210000,"p2MaxCents":125000,"p2MinCents":100000,"p3MaxCents":60000,"p3MinCents":45000,"p4MaxCents":20000,"p4MinCents":15000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eTarget Information\u003c/h2\u003e\n\n\u003cp\u003eAny target on the Volkswagen Germany domain is considered as in scope for this program. \u003c/p\u003e","rewardRangeData":{"1":{"min":2100,"max":2500},"2":{"min":1000,"max":1250},"3":{"min":450,"max":600},"4":{"min":150,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null},{"id":"0a4bae94-4054-4bd2-9864-6836ee12d1ec","name":"Out of scope targets","targets":[{"id":"faba37e4-073c-4462-a51f-11e3eea2b264","uri":"https://erwin.volkswagen.de","name":"erwin.volkswagen.de","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"db3f0057-fec9-4908-ac61-23c832ccca2b","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eerwin.volkswagen.de is currently out of scope, except for findings where you can demonstrate an impact on other systems (e.g. RCE, SSRF, Cookie stealing on volkswagen.de).\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"d71e802d-61d5-4bf5-bacb-24b0fd3d7cd7","code":"volkswagen-og","state":"in_progress","endsAt":null,"bountyId":"e8e0966c-033b-4f77-8ff8-92d7367022b8","startsAt":"2021-06-15T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Automotive","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/1199/60d0/cdb7d113/ce93c64ae822edead943abc3f6a4d1b9_Volkswagen_logo_2019.svg.png","logoBackgroundColor":"#ffffff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2026-01-06T11:25:32.118Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/volkswagen-og","changelogs":"/engagements/volkswagen-og/changelog","submissions":null,"announcements":"/engagements/volkswagen-og/announcements","hallOfFame":"/engagements/volkswagen-og/hall_of_fames","crowdstream":"/engagements/volkswagen-og/crowdstream"},"announcementsCount":14,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/volkswagen-og/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=volkswagen-og\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/volkswagen-og/engagement_subscribers","engagementChangelogsUrl":"/engagements/volkswagen-og/changelog","publishedAt":"2026-01-06T11:25:32.145Z","engagementChangelogUrl":"/engagements/volkswagen-og/changelog/6bc3d4da-d19f-4458-8135-ad3a020ac71e","createUserFeedbacksUrl":"/engagements/volkswagen-og/feedbacks","engagementCrowdstreamUrl":"/engagements/volkswagen-og/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}