Coordinated Disclosure Verified Alerts 228,413 coordinated disclosures
122,260 fixed vulnerabilities
184,382 websites, 16,765 VIP websites
6,176 researchers, 6,915 subscribers

Avito Bug Bounty Program

Avito runs a bug bounty program to ensure the highest security and privacy of its websites. Everyone is eligible to participate in the program subject to the below-mentioned conditions and requirements of Avito

Open Bug Bounty performs triage and verification of the submissions. However, we never intervene to the further process of vulnerability remediation and disclosure between Avito and researchers.

Bug bounty program allow private submissions only.

Bug Bounty Scope

The following websites are within the scope of the program:

m.avito.ru
avito.ru

Non-Intrusive Submissions Handling

The following section encompasses submission of the vulnerabilities that do not require intrusive testing as per Open Bug Bounty rules:

- Cross Site Scripting (XSS)
- Open Redirect

- Cross Site Request Forgery (CSRF)
- Improper Access Control

General Requirements:

Out-of-scope vulnerabilities:
- Reports from automated scanners without appropriate analysis or demonstration of security impacts
- Reports about outdated/vulnerable software without exploitation examples
- Self-XSS affecting only current user
- Missing CSRF token in forms, where sensitive information like user data cannot be modified (e.g. logout form)
- Issues related to window.opener
- Session hijacking, session timeout
- Missing security HTTP headers (X-Frame-*, X-Content-*, CSP, HSTS, HPKP)
- Missing SPF, DKIM, DMARC records
- Missing "HttpOnly", "secure", "SameSite" flags for non-sensitive cookies
- Possibilities for exhaustive search by user/item identifiers

Testing Requirements:

Strictly prohibited:
- Searching for vulnerabilities in out-of-scope and 3rd-party services, including payment gateways
- DoS/DDoS/physical access/phishing/social engineering attacks
- Stealing regular users' accounts and performing any other actions affecting their security
- Publishing any sensitive information discovered during security testing

Possible Awards:

Currently only Kudos.

Community Rating

Provided by security researchers who reported security vulnerabilities via this bug bounty program:

 
Response Time  How quickly researchers get responses to their submissions.
Remediation Time  How quickly reported submissions are fixed.
Cooperation and Respect  How fairly and respectfully researchers are being treated.


  Latest VIP Submissions

massaget.kz
Reported by ELProfesor Helped patch 739 vulnerabilities
Received 6 Coordinated Disclosure badges
Received 34 recommendations
on 19.06.2018
templatemonster.com
Reported by ELProfesor Helped patch 739 vulnerabilities
Received 6 Coordinated Disclosure badges
Received 34 recommendations
on 19.06.2018
fnde.gov.br
Reported by Gh05tPT Helped patch 129 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 3 recommendations
on 19.06.2018
spark.co.nz
Reported by Spam404 Helped patch 14240 vulnerabilities
Received 9 Coordinated Disclosure badges
Received 67 recommendations
on 19.06.2018
ilportaledellautomobilista.it
Reported by Spam404 Helped patch 14240 vulnerabilities
Received 9 Coordinated Disclosure badges
Received 67 recommendations
on 19.06.2018
vegvesen.no
Reported by Spam404 Helped patch 14240 vulnerabilities
Received 9 Coordinated Disclosure badges
Received 67 recommendations
on 19.06.2018
netsarang.com
Reported by OmniGooch Helped patch 2217 vulnerabilities
Received 5 Coordinated Disclosure badges
Received 8 recommendations
on 19.06.2018
onlineserieswatch.com
Reported by ELProfesor Helped patch 739 vulnerabilities
Received 6 Coordinated Disclosure badges
Received 34 recommendations
on 18.06.2018
hoc24.vn
Reported by login_denied Helped patch 1597 vulnerabilities
Received 7 Coordinated Disclosure badges
Received 41 recommendations
on 18.06.2018
printbar.ru
Reported by login_denied Helped patch 1597 vulnerabilities
Received 7 Coordinated Disclosure badges
Received 41 recommendations
on 18.06.2018



  Latest Submissions

iari.res.in
Reported by Sudi Helped patch 0 vulnerabilities
Received 0 Coordinated Disclosure badges
on 19.06.2018
sei.cijun.sp.gov.br
Reported by Gh05tPT Helped patch 129 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 3 recommendations
on 19.06.2018
cpcb.nic.in
Reported by Sudi Helped patch 0 vulnerabilities
Received 0 Coordinated Disclosure badges
on 19.06.2018
softwarepublico.gov.br
Reported by Gh05tPT Helped patch 129 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 3 recommendations
on 19.06.2018
sei-teste.processoe...ronico.nuvem.gov.br
Reported by Gh05tPT Helped patch 129 vulnerabilities
Received 4 Coordinated Disclosure badges
Received 3 recommendations
on 19.06.2018
thistown.nz
Reported by Sudi Helped patch 0 vulnerabilities
Received 0 Coordinated Disclosure badges
on 19.06.2018
bata.in
Reported by ELProfesor Helped patch 739 vulnerabilities
Received 6 Coordinated Disclosure badges
Received 34 recommendations
on 19.06.2018
drogasil.com.br
Reported by JulioCesar Helped patch 277 vulnerabilities
Received 3 Coordinated Disclosure badges
Received 2 recommendations
on 19.06.2018
blackliontyres.nz
Reported by Sudi Helped patch 0 vulnerabilities
Received 0 Coordinated Disclosure badges
on 19.06.2018
directory.unca.edu
Reported by willc Helped patch 0 vulnerabilities
Received 0 Coordinated Disclosure badges
on 19.06.2018