Bug Bounty Program - BlaBlaCar

Bug Bounty Program - BlaBlaCar

Bounty USD $50 - $3,000

Program Details

Handle
bug-bounty-program-blablacar

Scope (11 targets)

web: 4 mobile: 4 api: 3

In Scope

  • https://edge.blablacar.(fr|de|co.uk|in|es|mx|be|hr|hu|it|nl|pl|com.br|pt|ro|ru|com|tr|com.ua)) api bounty-eligible
  • https://auth.blablacar.(fr|de|co.uk|in|es|mx|be|hr|hu|it|nl|pl|com.br|pt|ro|ru|com|tr|com.ua) api bounty-eligible
  • https://www.blablacar.(fr|de|co.uk|in|es|mx|be|hr|hu|it|nl|pl|com.br|pt|ro|ru|com|tr|com.ua) web bounty-eligible
  • https://m.blablacar.(fr|de|co.uk|in|es|mx|be|hr|hu|it|nl|pl|com.br|pt|ro|ru|com|tr|com.ua) web bounty-eligible
  • https://play.google.com/store/apps/details?id=com.comuto&hl=en mobile bounty-eligible
  • https://itunes.apple.com/fr/app/blablacar-trusted-carpooling/id341329033?l=en&mt=8 mobile bounty-eligible
  • https://api.blablalines.com api bounty-eligible
  • https://daily.blablacar.fr web bounty-eligible
  • https://blablacardaily.com web bounty-eligible
  • https://play.google.com/store/apps/details?id=com.blablalines mobile bounty-eligible
  • https://apps.apple.com/fr/app/blablalines-covoiturage/id1225543288 mobile bounty-eligible

Out of Scope

Any website that is not listed explicitly in the scope., However, though listed in the out-of-scope list, if you really feel that a bug will leave an impact on our platform, please come up with a convincing and working POC. If that convinces us to change our code, we will reward you with a bounty., Finally, fraud related reports are out-of-scope if they do not exploit a security vulnerability. Therefore, fraud activity enabled by bug or incomplete business rules enforcement are out-of-scope. However, a fraud activity enabled by a CSRF exploit for example is valid.

Additional Info

Sources
yeswehack