Skip to content

[Program]: Vivid #169

Description

@KaranSRMA

Company

Vivid

Program URL

https://vivid.money/en-eu/bug-bounty/

Contact

bugbounty@vivid.money

Description

When searching for vulnerabilities in Vivid Money applications and services, should be to follow the rules:
For testing should use only your own accounts.
You are allowed to use the credentials of other users for testing, provided that they have explicitly agreed to provide the credentials.
Vivid Money does not issue additional accesses and accounts (including test accounts) for testing.

Rewards

  • *bounty
  • *recognition
  • *swag

Program type

bounty

Status

active

Safe harbor

full

Allows disclosure

false

Domains

*.vivid.money
Mobile Application iOS: https://apps.apple.com/de/app/id1504417378
Mobile Application Android: https://play.google.com/store/apps/details?id=vivid.money

Structured scope

No response

Out of scope

No response

Excluded methods

  • dos
  • social_engineering
  • phishing
  • physical_access
  • automated_scanning

Requires account

No response

Minimum payout

No response

Maximum payout

No response

Currency

No response

Payout - critical

No response

Payout - high

No response

Payout - medium

No response

Payout - low

No response

Swag details

No response

Testing policy URL

No response

Response SLA days

14

Disclosure timeline days

No response

Legal terms URL

No response

Hall of fame URL

No response

Reporting URL

No response

PGP key URL

No response

Preferred languages

No response

Standards

No response

Confirmation

  • I confirm the information is accurate and I have included only publicly documented program details.

Metadata

Metadata

Assignees

No one assigned

    Labels

    submission-processedBot has parsed this submission and opened a PR

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions