Coordinated and Responsible Vulnerability Disclosure Free Bug Bounty Program 477,572 coordinated disclosures
257,451 fixed vulnerabilities
634 bug bounties with 1261 websites
13,031 researchers, 1001 honor badges

CultivateAI Bug Bounty Program

CultivateAI runs a bug bounty program to ensure the highest security and privacy of its websites. Everyone is eligible to participate in the program subject to the below-mentioned conditions and requirements of CultivateAI

Open Bug Bounty performs triage and verification of the submissions. However, we never intervene to the further process of vulnerability remediation and disclosure between CultivateAI and researchers.

Bug bounty program allow private and public submissions.

Bug Bounty Scope

The following websites are within the scope of the program:

trycultivate.com

Non-Intrusive Submissions Handling

The following section encompasses submission of the vulnerabilities that do not require intrusive testing as per Open Bug Bounty rules:

- Cross Site Scripting (XSS)
- Open Redirect

- Cross Site Request Forgery (CSRF)
- Improper Access Control

General Requirements:

If you find a vulnerability please submit a description of the vulnerability and steps to reproduce. If possible please provide additional resources such as logs, screenshots and proof of concept code.

Apps in Scope:
* https://app.trycultivate.com/

Testing Requirements:

Do not:
* DoS/DDoS/phishing/social engineering attacks
* Run automated scans without explicit permission from Cultivate
* Engage with our end-users or customers
* Attack Cultivate offices or other physical premises
* Publishing ANY sensitive information discovered during security testing

More details to be written...

Possible Awards:

A big thank you from the team. We do not have any monetary compensation at this time.

Special Notes:

If you need additional details or have any questions please do not hesitate to contact us.

Community Rating

Provided by security researchers who reported security vulnerabilities via this bug bounty program:

 
Response Time  How quickly researchers get responses to their submissions.
Remediation Time  How quickly reported submissions are fixed.
Cooperation and Respect  How fairly and respectfully researchers are being treated.

Researcher's comments

No comments so far.

  Latest Patched

 15.12.2019 usp.ac.fj
 14.12.2019 har.com
 14.12.2019 hackaday.io
 13.12.2019 alamy.com
 13.12.2019 gnu.org
 13.12.2019 womensecret.com
 13.12.2019 chrono24.com
 13.12.2019 minube.com
 12.12.2019 loveholidays.com
 12.12.2019 team.georgia.gov

  Latest Blog Posts

27.11.2019 by TahakhanTaha
Reflected xss in 360totalsecurity
21.11.2019 by TahakhanTaha
blind xss in apple
30.10.2019 by Nep_1337_1998
Denial of Service vulnerability in script-loader.php (CVE-2018-6389)
17.10.2019 by 0xrocky
Stored XSS
17.10.2019 by geeknik
The "S" in IOT is for Security

  Recent Recommendations

    10 December, 2019
     jnswbr:
Vielen Dank für den XSS-Hinweis.
Der Fehler wurde umgehend korrigiert!
    10 December, 2019
     xo_shopsoftware:
Helped us quickly to fix an open GIT exploit on our website.
Many thanks to your work!
    10 December, 2019
     cyberday_gmbh:
thanks for reporting the xss issue
    9 December, 2019
     TristanGuiheux:
Kenan G. has helped us to find and fix some issues on web sites we're protecting. This kind of help is greatly appreciated from a security perspective. This way we can improve ourselves and protect our customers. Thanks again in my name.
    6 December, 2019
     r0m01736939:
Thank you for your report. I was able to fix it quickly :)