11/04/2022
Holdthesugar
Bounty: $25 -$1000
Category: CMS, eCommerce, Payments, User Accounts
Hold the Sugar is an online bakery making all your favorite cakes and treats Sugar-free! Only the main Holdthesugar website holdthesugar.eu is included within the scope.
IMPORTANT
Do NOT run automated scans with tools like ZAP, Burp Scanner, Acunetix, and such. You will not be awarded a bounty if we detect that you used automated tools even if you report a valid bug!
JavaScript vulnerabilities must be demonstrated with more than just “alert()”.
All domains/subdomains/subnets not explicitly stated as in scope are considered out of scope.
The following vulnerabilities are considered out of scope:
Social engineering attacks.
Brute-force/dictionary attacks.
Non-sensitive Clickjacking.
Non-sensitive CSRF (login/logout).
Vulnerabilities without a POC (Proof of Concept).
Physical access-dependent attacks.
MITM-dependent attacks.
Best practices in SSL/TLS configuration, implementations….etc
Industry standards and policies.
Disruption of the service or to the website (for example, DoS attacks, mass scans …etc).
Rate-limiting issues.
Automated reports from tools like Nmap, Nessus …etc.
SUBMISSION Please ensure the submitted vulnerabilities/bugs are reproducible.
Provide as much information as possible and add screenshots when needed. Clear reports get validated quicker, and therefore you’ll get your bounty faster.
DISCLOSURE
Do not share any information/data related to the tests you carry out without express permission from NoLemons.
11/04/2022