{"id":"e1932318-5130-4a41-9a7e-35cbd77e5015","engagementId":"32db6506-e335-4c0f-b02e-d7130e4d4299","data":{"brief":{"id":"81eda0da-c6e2-4e85-97c9-18abfaecf193","name":"VR Public Managed Bug Bounty Engagement","tagline":"VR, a Finnish state-owned company, focuses on responsible transport, ensuring smooth daily and leisure travel, transporting 23.4 million tonnes of goods in 2023, and promoting well-being through electric rail and city traffic.","description":"\u003cp\u003eWe are a modern passenger, logistics and maintenance service company owned by the Finnish state which operates in Finland and Sweden.\u003c/p\u003e\n\n\u003cp\u003ePlease follow the rules detailed in this page to prevent unforeseen security problems to the clients of VR, their data or the business of the VR Group.\u003c/p\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003e\u003cem\u003eFor the initial prioritization/rating of findings, this engagement will use the \u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Vulnerability Rating Taxonomy\u003c/a\u003e. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch2\u003eEngagement Guidelines\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eTo gain the biggest bounty you need to be for example able to gain access to most or all client data or their personal details, or are able to misuse their payment methods. This will require a well-documented proof of concept code\u003c/li\u003e\n\u003cli\u003eIf the vulnerability reported does not create a risk or is not a security issue, we reserve the right to not award a bounty\u003c/li\u003e\n\u003cli\u003eIf the vulnerability is in a publicly available and widely used library, we may award a bounty which is smaller than usual\u003c/li\u003e\n\u003cli\u003eIf you report to us several vulnerabilities which turn to be different versions of the same root cause vulnerability, or the vulnerability is a smaller aspect of a bigger vulnerability, these reports can be combined for determining the bounty. Due to regulations, we interact with the original reporter only when discussing the reported vulnerabilities\u003c/li\u003e\n\u003c/ul\u003e","industryTagId":"2bf483dc-2f0b-4e2d-b7f0-568b8cc28809","targetsOverview":"\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of VR Group not listed in the targets section is out of scope. This includes any/all subdomains not listed above. If you happen to identify a security vulnerability on a target that is not in scope, but it demonstrably belongs to VR Group, you can report it to this engagement. However, be aware that it is ineligible for rewards or points-based compensation.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWe are interested in all kinds of privacy issues, protection of client data and information from unauthorized disclosure to data loss, problems with the protection of client ticketing information.\u003c/li\u003e\n\u003cli\u003ePayment system security, payment method handling and/or loss or abuse of payment methods.\u003c/li\u003e\n\u003cli\u003eMethods of blocking, slowing down or causing other availability issues to the systems.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eReports on issues, which cause small monetary losses or a small number of discounted tickets to be issued, or other problems with small business impact may not be eligible for bounties.\u003c/em\u003e\u003c/p\u003e\n\n\u003ch2\u003eAccess\u003c/h2\u003e\n\n\u003cp\u003eWhen conducting any automated testing or scans, use a reasonable rate for sending requests. Do not send unnecessarily many requests in a quick succession. When conducting automated testing, include the following header in requests:\u003c/p\u003e\n\n\u003cp\u003e\u003ccode\u003eX-VR-BB: bugcrowd-\u0026lt;your-bugcrowd-username\u0026gt;\u003c/code\u003e\u003c/p\u003e\n\n\u003cp\u003eWhen sending occasional, single requests, the header is not needed, but we recommend always including it during testing.\u003c/p\u003e\n\n\u003ch2\u003eCredentials\u003c/h2\u003e\n\n\u003cp\u003eTo gain access to the application, please sign up for an account using your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\n\u003ch2\u003eExcluded Submission Types\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://bugcrowd.com/vulnerability-rating-taxonomy\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eP5 vulnerabilities\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvailability/volumetric testing e.g.:\n\n\u003cul\u003e\n\u003cli\u003eDDoS/Network DoS (application level or misconfiguration DoS is allowed if the PoC doesn't disrupt business)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eCode injections to the backend systems (for example SQL-injection) where the data in the backend is changed or deleted, or read in unnecessary quantities. Code injections themselves are allowed, the limitation is the to the functionality and scope of the research and Proof of Concept code. For example, you can read some data to demonstrate the vulnerability but do not dump all the data, nor delete or change any data.\u003c/li\u003e\n\u003cli\u003eReport by an automated scanner, which in general are very speculative and tentative.\u003c/li\u003e\n\u003cli\u003eConfiguration issues with email servers (SPF, DMARC, ...)\u003c/li\u003e\n\u003cli\u003eSSL/TLS configuration best practices or the lack of them (unless there is a clear and demonstrable vulnerability).\u003c/li\u003e\n\u003cli\u003eIssues related to SSL/TLS configuration which are found by SSLabs scanner or similar.\u003c/li\u003e\n\u003cli\u003eBest practices or the lack of them related to HTTP security headers.\u003c/li\u003e\n\u003cli\u003eForms with a theoretical CSRF vulnerability. CSRF vulnerabilities with a clear impact and a working PoC may be accepted.\u003c/li\u003e\n\u003cli\u003eLogout CSRF\u003c/li\u003e\n\u003cli\u003eReports related to password strength or quality.\u003c/li\u003e\n\u003cli\u003eWeb contents spoofing or text injection\u003c/li\u003e\n\u003cli\u003eInformation disclosure of version numbers or similar, which are not related to a definite exploitable vulnerability.\u003c/li\u003e\n\u003cli\u003eReports related to cookies and their configuration.\u003c/li\u003e\n\u003cli\u003eIssues in error page configuration.\u003c/li\u003e\n\u003cli\u003eSelf-XSS and XSS with no possible security impact\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eN-day/Third party 0-day Policy\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWhen N-Day bugs are released to the public, we will consider these as in scope after 14 days has gone by\n\n\u003cul\u003e\n\u003cli\u003ee.g: N-day released on 01/01/2025, we would consider it in-scope on 01/15/2025\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eOut of Scope\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eInteracting or manipulate other stakeholders and their associated accounts including:\n\n\u003cul\u003e\n\u003cli\u003eSocial engineering attacks\u003c/li\u003e\n\u003cli\u003ePhishing attacks\u003c/li\u003e\n\u003cli\u003ePhysical attacks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eThird party providers and services\u003c/li\u003e\n\u003cli\u003eActions and methods that cause, or will probably cause, disruption to the business.\u003c/li\u003e\n\u003cli\u003eAny actions that threaten the security of an individual persons.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eLeaked Credentials\u003c/h2\u003e\n\n\u003cp\u003eIf you happen to identify leaked credentials that are VR Group related (example.name@vr.fi) or other VR Group related users, we appreciate you reporting it to this program, but in most cases no bounty is awarded for this to not encourage obtaining leaked credentials through illegal means. This policy helps maintain the highest standard of operational confidentiality, integrity, and compliance.\u003c/p\u003e\n\n\u003ch2\u003eVR Group employees\u003c/h2\u003e\n\n\u003cp\u003eIf you are a VR Group employee or otherwise working with VR Group, you are allowed to participate in the Bug Bounty Program, but you must include your name and indicate this in the bug report.\u003c/p\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire through the \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support Portal\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"dbe926e5-ed53-4410-9629-e052eadea0d9","name":"In Scope ","targets":[{"id":"2ff4fe86-65d5-4f7f-988e-35650d2e0149","uri":"https://www.vr.fi/","name":"www.vr.fi","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"54ad6ff7-24ab-4ec1-8630-6c40937c1977","sortOrder":1},"sortOrder":1,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"2ff4fe86-65d5-4f7f-988e-35650d2e0149"},{"id":"e8a0921a-8c3b-463d-af43-8dbdc6b1c03d","name":"NodeJS","targetId":"2ff4fe86-65d5-4f7f-988e-35650d2e0149"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"c28b08a2-e8ec-4f6f-85fd-b299cdb7d66b","p1MaxCents":500000,"p1MinCents":250000,"p2MaxCents":160000,"p2MinCents":100000,"p3MaxCents":60000,"p3MinCents":40000,"p4MaxCents":20000,"p4MinCents":10000,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":null},"descriptionHtml":"\u003ch2\u003eDescription\u003c/h2\u003e\n\n\u003cp\u003eVr.fi is a site where customers can buy tickets for trains and get information about train schedules, alerts and locations. It is possible for our customers to create accounts and for us it is important that customer data is kept safe and that the integrity of our ticketing system is not compromised.\u003c/p\u003e","rewardRangeData":{"1":{"min":2500,"max":5000},"2":{"min":1000,"max":1600},"3":{"min":400,"max":600},"4":{"min":100,"max":200},"5":{"min":null,"max":null}},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"32db6506-e335-4c0f-b02e-d7130e4d4299","code":"vr-group-mbb-og1","state":"in_progress","endsAt":null,"bountyId":"8490bb2a-9659-4354-bc3e-0e87cdb62f62","startsAt":"2025-10-21T18:00:00Z"},"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Transportation","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/f899/5077/54d0f97e/b733a44e03bd5762627882c0be06ea30_vrgroup_logo.jpeg","logoBackgroundColor":"#fff","displayDisclosureTerms":true,"coordinatedDisclosure":true,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2025-10-23T10:47:41.238Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/vr-group-mbb-og1","changelogs":"/engagements/vr-group-mbb-og1/changelog","submissions":null,"announcements":"/engagements/vr-group-mbb-og1/announcements","hallOfFame":"/engagements/vr-group-mbb-og1/hall_of_fames","crowdstream":"/engagements/vr-group-mbb-og1/crowdstream"},"announcementsCount":1,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/vr-group-mbb-og1/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=vr-group-mbb-og1\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/vr-group-mbb-og1/engagement_subscribers","engagementChangelogsUrl":"/engagements/vr-group-mbb-og1/changelog","publishedAt":"2026-09-23T09:47:05.388Z","engagementChangelogUrl":"/engagements/vr-group-mbb-og1/changelog/e1932318-5130-4a41-9a7e-35cbd77e5015","createUserFeedbacksUrl":"/engagements/vr-group-mbb-og1/feedbacks","engagementCrowdstreamUrl":"/engagements/vr-group-mbb-og1/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":true,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}