Coordinated and Responsible Vulnerability Disclosure Free Bug Bounty Program 475,406 coordinated disclosures
255,765 fixed vulnerabilities
634 bug bounties with 1261 websites
12,966 researchers, 996 honor badges

Lidl Digital Bug Bounty Program

Lidl Digital runs a bug bounty program to ensure the highest security and privacy of its websites. Everyone is eligible to participate in the program subject to the below-mentioned conditions and requirements of Lidl Digital

Open Bug Bounty performs triage and verification of the submissions. However, we never intervene to the further process of vulnerability remediation and disclosure between Lidl Digital and researchers.

Bug bounty program allow private and public submissions.

Bug Bounty Scope

The following websites are within the scope of the program:

*.lidl-shop.sk
lidl-sklep.pl
lidlonline.es
*.lidl.de
*.lidl-shop.cz
*.lidl-shop.nl
*.lidl-shop.be

Non-Intrusive Submissions Handling

The following section encompasses submission of the vulnerabilities that do not require intrusive testing as per Open Bug Bounty rules:

- Cross Site Scripting (XSS)
- Open Redirect

- Cross Site Request Forgery (CSRF)
- Improper Access Control

General Requirements:

All kind of issues can be reported

Testing Requirements:

Dont use exessive brute force Scanners and dont fill out to many form fields, since it may create internal emails

Possible Awards:

nothing yet

Community Rating

Provided by security researchers who reported security vulnerabilities via this bug bounty program:

 
Response Time  How quickly researchers get responses to their submissions.
Remediation Time  How quickly reported submissions are fixed.
Cooperation and Respect  How fairly and respectfully researchers are being treated.

Researcher's comments

    30 October, 2019
    Kenan:
please remove this company from "bug bounty list", they don't have bug bounty, also as they promised they didn't reward

  Latest Patched

 09.12.2019 burdastyle.ru
 09.12.2019 newtonnc.gov
 09.12.2019 gilacountyaz.gov
 09.12.2019 teamunify.com
 09.12.2019 karar.com
 09.12.2019 sd26.senate.ca.gov
 09.12.2019 legislature.mi.gov
 09.12.2019 dailyverses.net
 09.12.2019 gamepedia.jp
 09.12.2019 brickset.com

  Latest Blog Posts

30.11.2019 by IAMMUSTAFAQADRI
How to hack an app: 8 best practices for pen testing mobile apps
27.11.2019 by TahakhanTaha
Reflected xss in 360totalsecurity
21.11.2019 by TahakhanTaha
blind xss in apple
30.10.2019 by Nep_1337_1998
Denial of Service vulnerability in script-loader.php (CVE-2018-6389)
17.10.2019 by 0xrocky
Stored XSS

  Recent Recommendations

    9 December, 2019
     TristanGuiheux:
Kenan G. has helped us to find and fix some issues on web sites we're protecting. This kind of help is greatly appreciated from a security perspective. This way we can improve ourselves and protect our customers. Thanks again in my name.
    6 December, 2019
     r0m01736939:
Thank you for your report. I was able to fix it quickly :)
    6 December, 2019
     Buchabstauber:
We would like to thank you for your valuable contribution in finding the XSS issue on our site! You have been very helpful!
    4 December, 2019
     fablabc:
Thanks for reporting a high risky issue to me. You are awesome
    4 December, 2019
     lbl_jd:
Gh05tPT found a XSS vulnerability on our site which I was able to fix quite quickly. Thanks for your help.