Coordinated and Responsible Vulnerability Disclosure Free Bug Bounty Program 278,707 coordinated disclosures
160,195 fixed vulnerabilities
223,633 websites, 17,621 VIP websites
7,438 researchers, 6,915 subscribers

Avito Bug Bounty Program

Avito runs a bug bounty program to ensure the highest security and privacy of its websites. Everyone is eligible to participate in the program subject to the below-mentioned conditions and requirements of Avito

Open Bug Bounty performs triage and verification of the submissions. However, we never intervene to the further process of vulnerability remediation and disclosure between Avito and researchers.

Bug bounty program allow private submissions only.

Bug Bounty Scope

The following websites are within the scope of the program:

m.avito.ru
avito.ru

Non-Intrusive Submissions Handling

The following section encompasses submission of the vulnerabilities that do not require intrusive testing as per Open Bug Bounty rules:

- Cross Site Scripting (XSS)
- Open Redirect

- Cross Site Request Forgery (CSRF)
- Improper Access Control

General Requirements:

Out-of-scope vulnerabilities:
- Reports from automated scanners without appropriate analysis or demonstration of security impacts
- Reports about outdated/vulnerable software without exploitation examples
- Self-XSS affecting only current user
- Missing CSRF token in forms, where sensitive information like user data cannot be modified (e.g. logout form)
- Issues related to window.opener
- Session hijacking, session timeout
- Missing security HTTP headers (X-Frame-*, X-Content-*, CSP, HSTS, HPKP)
- Missing SPF, DKIM, DMARC records
- Missing "HttpOnly", "secure", "SameSite" flags for non-sensitive cookies
- Possibilities for exhaustive search by user/item identifiers

Testing Requirements:

Strictly prohibited:
- Searching for vulnerabilities in out-of-scope and 3rd-party services, including payment gateways
- DoS/DDoS/physical access/phishing/social engineering attacks
- Stealing regular users' accounts and performing any other actions affecting their security
- Publishing any sensitive information discovered during security testing

Possible Awards:

Currently only Kudos.

Community Rating

Provided by security researchers who reported security vulnerabilities via this bug bounty program:

 
Response Time  How quickly researchers get responses to their submissions.
Remediation Time  How quickly reported submissions are fixed.
Cooperation and Respect  How fairly and respectfully researchers are being treated.

  Latest Patched

      elo7.com.br
    Patched on 17.10.2018
      engelvoelkers.com
    Patched on 17.10.2018
      iledefrance.fr
    Patched on 16.10.2018
      geizhals.at
    Patched on 16.10.2018
      search.custhelp.com
    Patched on 16.10.2018
      boattrader.com
    Patched on 16.10.2018
      bergfreunde.de
    Patched on 15.10.2018
      hirist.com
    Patched on 15.10.2018
      deskgram.org
    Patched on 15.10.2018
      playboyplus.com
    Patched on 15.10.2018

  Recent Recommendations

    17 October, 2018
     aartvdwerf:
Helped me fix 2 xss vulnerabilities. Very quick response.
    17 October, 2018
     Paruzzi_webm:
He pointed out a problem which we then could fix. Thanks again for al your help.
    16 October, 2018
     euvtechnology:
Dear Taha, Thank you for reporting the XSS vulnerability you discovered on our website and helping us ensuring the security of our webservices.
    16 October, 2018
     euvtechnology:
Dear Cole, Thank you for reporting the XSS vulnerability you discovered on our website and helping us ensuring the security of our webservices.
    16 October, 2018
     euvtechnology:
Dear Ketan, Thank you for reporting the XSS vulnerability you discovered on our website and helping us ensuring the security of our webservices.