{"id":"cdf0a5a7-3e14-4bd2-8997-a9567e0bb63e","engagementId":"1e0e0003-4cb7-4563-a7f1-286302de8b25","data":{"brief":{"id":"128a6196-eb76-4a25-a18f-f0abc744f036","name":"Web.com Bug Bounty","tagline":"You say it. We build it. It's as easy as Web.com! ","description":"\u003cp\u003eWeb.com provides many services and products targeted at small and medium sized businesses. No technology is perfect, and Web.com believes that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology. We are excited for you to participate as a security researcher to help us identify vulnerabilities in our web applications. Good luck and happy hunting!\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eEligibility\u003c/h2\u003e\n\n\u003cp\u003eYou may not participate in this program if you are an employee or family member of an employee, or a current vendor or employee of such vendor of Newfold Digital and any of its subsidiaries. You are also prohibited from participating if you are (i) in a country or territory that is the target of U.S. sanctions (including Cuba, Iran, Syria, North Korea, or the Crimea region of Ukraine), (ii) designated as a Specially Designated National or Blocked Person by the U.S. Department of the Treasury’s Office of Foreign Assets Control or otherwise owned, controlled, or acting on behalf of such a person or entity, or (iii) otherwise a prohibited party under U.S. trade and export control laws. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eRatings/Rewards\u003c/h2\u003e\n\n\u003cp\u003eThe program relies on CVSS to evaluate impact and determine reward allocations. It is essential to highlight that the priority of a vulnerability might be altered due to its likelihood or impact. \u003c/p\u003e\n\n\u003ctable\u003e\n\u003cthead\u003e\n\u003ctr\u003e\n\u003cth\u003eCVSS Score\u003c/th\u003e\n\u003cth\u003eVRT Classification\u003c/th\u003e\n\u003c/tr\u003e\n\u003c/thead\u003e\n\u003ctbody\u003e\n\u003ctr\u003e\n\u003ctd\u003e9.0-10.0\u003c/td\u003e\n\u003ctd\u003eP1-Critical\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e7.0-8.9\u003c/td\u003e\n\u003ctd\u003eP2-High\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e4.0-6.9\u003c/td\u003e\n\u003ctd\u003eP3-Medium\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e2.0-3.9\u003c/td\u003e\n\u003ctd\u003eP4-Low\u003c/td\u003e\n\u003c/tr\u003e\n\u003ctr\u003e\n\u003ctd\u003e0.0-1.9\u003c/td\u003e\n\u003ctd\u003eP5-Informational\u003c/td\u003e\n\u003c/tr\u003e\n\u003c/tbody\u003e\n\u003c/table\u003e\n\n\u003cp\u003eWe reserve the right to make any final determination of rating levels for any reported vulnerability. \u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eReport Formatting\u003c/h2\u003e\n\n\u003cp\u003eIn the \u003cstrong\u003eDescription\u003c/strong\u003e of a Vulnerability Report, please format the replication process as an \u003cstrong\u003eOrdered List\u003c/strong\u003e. Valid reports, formatted the following way, will be prioritized and accepted faster by Newfold Digital:\u003c/p\u003e\n\n\u003cblockquote\u003e\n\u003cp\u003eSteps To Reproduce: (Add details for how we can reproduce the issue) \u003c/p\u003e\n\n\u003cblockquote\u003e\n\u003col\u003e\n\u003cli\u003e[add step 1]\u003c/li\u003e\n\u003cli\u003e[add step 2]\u003c/li\u003e\n\u003cli\u003e[add step 3]...\u003c/li\u003e\n\u003c/ol\u003e\n\u003c/blockquote\u003e\n\u003c/blockquote\u003e","industryTagId":"46b8dcc8-bbd9-4a60-80ab-ab088c2bc3e4","targetsOverview":"\u003cp\u003e\u003cem\u003eTesting is only authorized on the targets listed as in scope. Any domain/property of Web.com not listed in the targets section is out of scope. This includes any/all subdomains not listed above.\u003c/em\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eAccess/Credentials\u003c/h2\u003e\n\n\u003cp\u003eThese websites are public facing. As these are production sites, please keep scanning during regular business hours (PDT) to a minimum so as not to affect regular business. For any areas that allow a signup you may use your @bugcrowdninja.com email address. For more info regarding @bugcrowdninja email addresses, see \u003ca href=\"https://docs.bugcrowd.com/researchers/participating-in-program/your-bugcrowdninja-email-address/\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003ehere\u003c/a\u003e. \u003c/p\u003e\n\n\u003cp\u003eNote:  You will not be reimbursed for any charges you may incur during signup or testing.\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eTesting Headers\u003c/h2\u003e\n\n\u003cp\u003ePlease include the following headers in all server requests. This will not affect the responses to your activity, but allows Web.com to identify Researcher testing activity and \u003cstrong\u003eavoid IP blocking\u003c/strong\u003e.\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eRequired\u003c/strong\u003e\u003cbr\u003e\n\u003ccode\u003eX-Request-Purpose: Research\u003c/code\u003e\u003c/p\u003e\n\n\u003cp\u003e\u003cstrong\u003eOptional\u003c/strong\u003e\u003cbr\u003e\n\u003ccode\u003eX-Bugcrowd-Ninja: [username]\u003c/code\u003e\u003c/p\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eProgram Rules\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eWeb.com and its subsidiaries maintain multiple website builders that allow you varying access to the HTML of your own page. XSS findings on these pages is not available for payout.\u003c/li\u003e\n\u003cli\u003eResearchers must provide a fully working non-malicious proof of concept that demonstrates a valid security impact to qualify for rewards.\u003c/li\u003e\n\u003cli\u003eInteracting with real customers or real customer accounts is forbidden. \u003c/li\u003e\n\u003cli\u003eWhen a vulnerability consists of different parameters but having the same endpoint, please group this together in the same report else will be considered as duplicate. \u003c/li\u003e\n\u003cli\u003eMultiple vulnerabilities caused by one underlying issue will be awarded one bounty (Ex: Centralized vulnerable parameters). \u003c/li\u003e\n\u003cli\u003eCross-Site Scripting (XSS) attacks are considered at maximum a medium severity. \u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eExcluded Submission Types\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eDDoS and Application DoS are not permitted\u003c/li\u003e\n\u003cli\u003eNo DMARC, nor SPF \u003c/li\u003e\n\u003cli\u003eOAuth session token is not invalidated on logout or password change/reset\u003c/li\u003e\n\u003cli\u003eOpen redirect vulnerabilities \u003c/li\u003e\n\u003cli\u003eError messages (e.g. verbose error messages, stack traces, application or server errors, version disclosure) \u003c/li\u003e\n\u003cli\u003eClickjacking \u003c/li\u003e\n\u003cli\u003ePlease do not test email spoofing\u003c/li\u003e\n\u003cli\u003eMissing or misconfigured HTTP security header \u003c/li\u003e\n\u003cli\u003eHTTP/DNS cache poisoning \u003c/li\u003e\n\u003cli\u003eCloudflare related issues \u003c/li\u003e\n\u003cli\u003eSelf-XSS reports will not be accepted\u003c/li\u003e\n\u003cli\u003eBroken links hosted on our website\u003c/li\u003e\n\u003cli\u003eSecrets such as API keys or passwords obtained from external aggregation/indexed data sources (e.g., dehashed.com or intelx.io) \u003c/li\u003e\n\u003cli\u003eCross-Site Request Forgery (CSRF) on unauthenticated forms or forms with non-sensitive actions (including logout CSRF) \u003c/li\u003e\n\u003cli\u003eRecently disclosed (\u0026lt;30 days) zero-day vulnerabilities. \u003c/li\u003e\n\u003cli\u003ePlease do not test chatboxes on the applications, etc. \u003c/li\u003e\n\u003cli\u003eUse of third-party vulnerable components\u003c/li\u003e\n\u003cli\u003eAnti Automation attacks, missing captcha, missing rate limiting, HTTP headers, SSL/TLS configuration and missing Secure flag on cookies are out of scope \u003c/li\u003e\n\u003cli\u003eAny source code disclosure\u003c/li\u003e\n\u003cli\u003eInfo.php (without providing an exploitable scenario) \u003c/li\u003e\n\u003cli\u003eSubdomain takeovers. Please submit any subdomain takeovers to our \u003ca href=\"https://bugcrowd.com/webdotcom-vdp\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eWeb.com VDP\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003chr\u003e\n\n\u003ch2\u003eSafe Harbor\u003c/h2\u003e\n\n\u003cp\u003e\u003cstrong\u003eWhen conducting vulnerability research according to this policy, we consider this research to be:\u003c/strong\u003e\u003c/p\u003e\n\n\u003cul\u003e\n\u003cli\u003eAuthorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy;\u003c/li\u003e\n\u003cli\u003eExempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls;\u003c/li\u003e\n\u003cli\u003eExempt from restrictions in our Terms \u0026amp; Conditions that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy; and\u003c/li\u003e\n\u003cli\u003eLawful, helpful to the overall security of the Internet, and conducted in good faith.\u003c/li\u003e\n\u003cli\u003eYou are expected, as always, to comply with all applicable laws.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003cp\u003e\u003cem\u003eIf at any time you have concerns or are uncertain whether your security research is consistent with this policy, please inquire via \u003ca href=\"https://bugcrowd-support.freshdesk.com/support/tickets/new\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBugcrowd Support\u003c/a\u003e before going any further.\u003c/em\u003e\u003c/p\u003e","safeHarborStatus":{"status":"full","label":"Safe harbor","description":"This engagement is fully committed to providing safe harbor for good-faith security research."},"collaborationEnabled":true,"additionalInformation":""},"scope":[{"id":"3ba48536-e102-4dcf-b94e-b93543b0dbbc","name":"In Scope ","targets":[{"id":"03363e46-6d50-401d-8c1f-cd15f003fa81","uri":"https://app.web.com","name":"app.web.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"30d96c6d-fa4a-49a3-a005-2a3363f889e0","sortOrder":0},"sortOrder":0,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"03363e46-6d50-401d-8c1f-cd15f003fa81"}],"recentChangeFlags":null},{"id":"9c051c01-aae5-4f1b-a602-a7f2b7e8371b","uri":"https://www.networksolutions.com","name":"www.networksolutions.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"29636015-6a4a-4225-98b8-ccbe361e4c4f","sortOrder":1},"sortOrder":1,"tags":[{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"9c051c01-aae5-4f1b-a602-a7f2b7e8371b"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"9c051c01-aae5-4f1b-a602-a7f2b7e8371b"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"9c051c01-aae5-4f1b-a602-a7f2b7e8371b"}],"recentChangeFlags":null},{"id":"69d8f7a9-f2d4-489f-b2f2-ef2ad3e17335","uri":"https://www.bluehost.com/","name":"https://www.bluehost.com/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"5fe563f8-2e16-4a5f-907b-25ec1880fb1c","sortOrder":2},"sortOrder":2,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"69d8f7a9-f2d4-489f-b2f2-ef2ad3e17335"}],"recentChangeFlags":null},{"id":"e8fe88f7-fff4-410c-bd62-7cc51ad4ff91","uri":"https://www.hostgator.com/","name":"https://www.hostgator.com/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"dc685c77-d06b-4210-b1be-ed27452f18e0","sortOrder":3},"sortOrder":3,"tags":[{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"e8fe88f7-fff4-410c-bd62-7cc51ad4ff91"}],"recentChangeFlags":null}],"inScope":true,"sortOrder":0,"description":null,"rewardRange":{"id":"f6472255-4c80-4ad2-85b0-e770359f6c9c","p1MaxCents":300000,"p1MinCents":200000,"p2MaxCents":150000,"p2MinCents":100000,"p3MaxCents":60000,"p3MinCents":25000,"p4MaxCents":null,"p4MinCents":null,"p5MaxCents":null,"p5MinCents":null,"engagementMaxCents":500000},"descriptionHtml":"\u003ch2\u003eOneWeb Platform\u003c/h2\u003e\n\n\u003cp\u003eWeb.com Group leverages its OneWeb platform across many of its web properties. Vulnerabilities found on different domains may be controlled by the same platform code.\u003c/p\u003e\n\n\u003ch2\u003eFocus Areas\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eapp.web.com(accessible via the website builder feature)\u003c/li\u003e\n\u003cli\u003eAI Features within\u003c/li\u003e\n\u003cli\u003eTest the website, servers and APIs related to the storefronts and account managers.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003ch2\u003eNote on User Authenticated Subdomains\u003c/h2\u003e\n\n\u003cul\u003e\n\u003cli\u003eAny subdomain flows (able to clearly showcase the navigation flow) after user authentication to the below listed targets are also \u003cstrong\u003ein-scope\u003c/strong\u003e \u003c/li\u003e\n\u003cli\u003eScope could change every couple months for all we know and known the wiser \u003c/li\u003e\n\u003c/ul\u003e","rewardRangeData":{"1":{"min":2000,"max":3000},"2":{"min":1000,"max":1500},"3":{"min":250,"max":600},"4":{"min":null,"max":null},"5":{"min":null,"max":null},"programMax":5000},"recentChangeFlags":null},{"id":"426353f8-3e6d-4049-b950-48d3ad39c15a","name":"Out of Scope Targets","targets":[{"id":"15e59f23-459e-4342-ab11-a30b302e58c3","uri":"https://*.web.com","name":"*.web.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"cb290485-fbf2-4334-84a3-2079df5257b7","sortOrder":0},"sortOrder":0,"tags":[{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"15e59f23-459e-4342-ab11-a30b302e58c3"},{"id":"3585ef4a-cd09-429b-ad25-5777064e59c5","name":"Moment.js","targetId":"15e59f23-459e-4342-ab11-a30b302e58c3"},{"id":"53917c1d-52c8-41f3-86f5-166e787ece8f","name":"Select2","targetId":"15e59f23-459e-4342-ab11-a30b302e58c3"},{"id":"5644ab16-c7ca-4ff7-ac95-383343dab77f","name":"MySQL","targetId":"15e59f23-459e-4342-ab11-a30b302e58c3"},{"id":"6481be19-8d64-4bb2-8426-2f1f7afe32e6","name":"Modernizr","targetId":"15e59f23-459e-4342-ab11-a30b302e58c3"},{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"15e59f23-459e-4342-ab11-a30b302e58c3"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"15e59f23-459e-4342-ab11-a30b302e58c3"},{"id":"abbd0575-727e-4565-8046-f7fa78eaf368","name":"PHP","targetId":"15e59f23-459e-4342-ab11-a30b302e58c3"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"15e59f23-459e-4342-ab11-a30b302e58c3"}],"recentChangeFlags":null},{"id":"a5742ade-e7a1-418c-b4ee-ebd05119b544","uri":"https://*.register.com","name":"*.register.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"e989945d-8eb2-4492-a262-bb5d7d37e25f","sortOrder":0},"sortOrder":0,"tags":[{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"a5742ade-e7a1-418c-b4ee-ebd05119b544"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"a5742ade-e7a1-418c-b4ee-ebd05119b544"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"a5742ade-e7a1-418c-b4ee-ebd05119b544"}],"recentChangeFlags":null},{"id":"be65032f-0e56-4d4d-95f8-a457d427a2f8","uri":"https://*.networksolutions.com","name":"*.networksolutions.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"5c809294-fb20-43b7-a8ba-71ec64d3b5e1","sortOrder":0},"sortOrder":0,"tags":[{"id":"29ad39e7-82e8-4428-8474-fdfb5ceeb8d5","name":"Cloudflare CDN","targetId":"be65032f-0e56-4d4d-95f8-a457d427a2f8"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"be65032f-0e56-4d4d-95f8-a457d427a2f8"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"be65032f-0e56-4d4d-95f8-a457d427a2f8"}],"recentChangeFlags":null},{"id":"fb969c12-4d2c-4551-a171-1a3465c2fc80","uri":"","name":" https://app.gator.com/","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"12777f68-baf3-48a8-995e-6c14099697df","sortOrder":0},"sortOrder":0,"tags":null,"recentChangeFlags":null},{"id":"5e3a8d16-914b-4bd9-8db0-261f7bf35716","uri":"","name":"*.bluehost.com","category":"website","ipAddress":null,"description":null,"engagementBriefTargetGroupTarget":{"id":"72a36636-fad9-4e8f-9b45-e370eec2cffd","sortOrder":0},"sortOrder":0,"tags":[{"id":"7ff6bfde-4352-4ff1-b376-565d898c283f","name":"nginx","targetId":"5e3a8d16-914b-4bd9-8db0-261f7bf35716"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"5e3a8d16-914b-4bd9-8db0-261f7bf35716"},{"id":"bc744424-2ab8-48c8-b938-c6d6abcdf500","name":"Website Testing","targetId":"5e3a8d16-914b-4bd9-8db0-261f7bf35716"}],"recentChangeFlags":null},{"id":"e8e5f495-8c0c-40d1-85c8-7b2223d0ef15","uri":"https://*.hostgator.com","name":"*.hostgator.com","category":"website","ipAddress":"","description":null,"engagementBriefTargetGroupTarget":{"id":"6005e152-fd09-44c5-a1d4-161112b9b5c4","sortOrder":0},"sortOrder":0,"tags":[{"id":"32a00682-97f0-4d01-852d-f06359bdc440","name":"Bootstrap","targetId":"e8e5f495-8c0c-40d1-85c8-7b2223d0ef15"},{"id":"9dded18a-fb38-4faa-b2ac-82845ca03735","name":"ReactJS","targetId":"e8e5f495-8c0c-40d1-85c8-7b2223d0ef15"},{"id":"a51a78cb-e0a6-4043-a736-335dec2d238c","name":"jQuery","targetId":"e8e5f495-8c0c-40d1-85c8-7b2223d0ef15"},{"id":"fbcf3656-e6af-403a-a14e-6ec830fb8668","name":"Javascript","targetId":"e8e5f495-8c0c-40d1-85c8-7b2223d0ef15"}],"recentChangeFlags":null}],"inScope":false,"sortOrder":1,"description":null,"rewardRange":null,"descriptionHtml":"\u003cp\u003eAny asset not explicitly listed in scope above falls outside this program. If you have found a vulnerability on an asset not covered here, we still want to hear from you — please submit it through our Vulnerability Disclosure Program using the relevant links below:\u003c/p\u003e\n\n\u003cp\u003e\u003ca href=\"https://www.networksolutions.com/disclosure\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eNetworkSolutions\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://www.hostgator.com/disclosure\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eHostgator\u003c/a\u003e\u003cbr\u003e\n\u003ca href=\"https://www.bluehost.com/disclosure\" rel=\"nofollow noreferrer\" target=\"_blank\"\u003eBluehost\u003c/a\u003e\u003c/p\u003e\n\n\u003cp\u003eReports submitted through these links will be reviewed by our security team.\u003c/p\u003e","rewardRangeData":{},"recentChangeFlags":null}],"resources":[],"engagement":{"id":"1e0e0003-4cb7-4563-a7f1-286302de8b25","code":"webdotcom","state":"in_progress","endsAt":null,"bountyId":"f7dd0e06-2193-4313-94e6-0b8a9aa6ffba","startsAt":"2017-04-13T19:00:00Z"},"vrtScopeRules":[],"engagementConfiguration":{"participation":"open","crowdSelectionStrategy":"none"}},"industryName":"Technology","methodologyName":null,"logoUrl":"https://logos.bugcrowdusercontent.com/logos/11c1/3c18/ae692a84/becbbdbeae7c1a3b8507143c2d373e2d_webdotcom_gimp.jpg","logoBackgroundColor":"#2D72B4","displayDisclosureTerms":true,"coordinatedDisclosure":false,"collaborationEnabled":true,"participation":"open","rewardAllocation":"pay_for_success","engagementTypeDetail":{"iconVariant":"bug-bounty","productLabel":"Bug Bounty","timeboxed":false},"pausedReason":null,"lastTransitionAt":"2017-04-13T19:00:00.000Z","cancellationReason":null,"statusLabel":"In progress","routesPaths":{"brief":"/engagements/webdotcom","changelogs":"/engagements/webdotcom/changelog","submissions":null,"announcements":"/engagements/webdotcom/announcements","hallOfFame":"/engagements/webdotcom/hall_of_fames","crowdstream":"/engagements/webdotcom/crowdstream"},"announcementsCount":15,"knownIssuesEnabled":true,"isDemo":false,"serviceLevel":"Platform","submitReportUrl":"/engagements/webdotcom/submissions/new","methodologyUrl":null,"progressPercentage":0,"badgeVariant":null,"userBannedFromEngagement":null,"isLoggedIn":false,"loginUrl":"/user/sign_in","scopedSubmissionsUrl":"/submissions?engagement%5B%5D=webdotcom\u0026sort%5B%5D=submitted-desc","isFollowing":null,"credentialsUrl":null,"toggleSubscriptionUrl":"/webdotcom/engagement_subscribers","engagementChangelogsUrl":"/engagements/webdotcom/changelog","publishedAt":"2026-09-11T15:03:27.462Z","engagementChangelogUrl":"/engagements/webdotcom/changelog/cdf0a5a7-3e14-4bd2-8997-a9567e0bb63e","createUserFeedbacksUrl":"/engagements/webdotcom/feedbacks","engagementCrowdstreamUrl":"/engagements/webdotcom/crowdstream","acceptedSubmissionsEnabled":true,"disclosedReportsEnabled":false,"engagementsUrl":"/engagements","engagementPaymentDetailUrl":null,"shouldShowHideButton":false,"engagementHiddenData":{},"totalRewardPool":null,"vrtScopeRules":{"data":[]},"vrtVersion":"1.19.1","isSubmissionPublishThrottled":false,"showIdVerificationAlert":false,"identityVerificationSettingsUrl":"https://bugcrowd.com/h/settings/identity_verification","identityUrl":null}