Coordinated and Responsible Vulnerability Disclosure Free Bug Bounty Program 477,574 coordinated disclosures
257,451 fixed vulnerabilities
634 bug bounties with 1261 websites
13,031 researchers, 1001 honor badges

CESA6 Bug Bounty Program

CESA6 runs a bug bounty program to ensure the highest security and privacy of its websites. Everyone is eligible to participate in the program subject to the below-mentioned conditions and requirements of CESA6

Open Bug Bounty performs triage and verification of the submissions. However, we never intervene to the further process of vulnerability remediation and disclosure between CESA6 and researchers.

Bug bounty program allow private submissions only.

Bug Bounty Scope

The following websites are within the scope of the program:

somerset.k12.wi.us

Non-Intrusive Submissions Handling

The following section encompasses submission of the vulnerabilities that do not require intrusive testing as per Open Bug Bounty rules:

- Cross Site Scripting (XSS)
- Open Redirect

- Cross Site Request Forgery (CSRF)
- Improper Access Control

General Requirements:

At this time, we are happy to hear about any vulnerabilities

Testing Requirements:

Do not use any tools that might be designed to test a site under a heavy load or induce a Denial of Service

Possible Awards:

Reward program is currently under consideration from management. Possible Awards will be updated soon

Community Rating

Provided by security researchers who reported security vulnerabilities via this bug bounty program:

 
Response Time  How quickly researchers get responses to their submissions.
Remediation Time  How quickly reported submissions are fixed.
Cooperation and Respect  How fairly and respectfully researchers are being treated.

Researcher's comments

No comments so far.

  Latest Patched

 15.12.2019 usp.ac.fj
 14.12.2019 har.com
 14.12.2019 hackaday.io
 13.12.2019 alamy.com
 13.12.2019 gnu.org
 13.12.2019 womensecret.com
 13.12.2019 chrono24.com
 13.12.2019 minube.com
 12.12.2019 loveholidays.com
 12.12.2019 team.georgia.gov

  Latest Blog Posts

27.11.2019 by TahakhanTaha
Reflected xss in 360totalsecurity
21.11.2019 by TahakhanTaha
blind xss in apple
30.10.2019 by Nep_1337_1998
Denial of Service vulnerability in script-loader.php (CVE-2018-6389)
17.10.2019 by 0xrocky
Stored XSS
17.10.2019 by geeknik
The "S" in IOT is for Security

  Recent Recommendations

    10 December, 2019
     jnswbr:
Vielen Dank für den XSS-Hinweis.
Der Fehler wurde umgehend korrigiert!
    10 December, 2019
     xo_shopsoftware:
Helped us quickly to fix an open GIT exploit on our website.
Many thanks to your work!
    10 December, 2019
     cyberday_gmbh:
thanks for reporting the xss issue
    9 December, 2019
     TristanGuiheux:
Kenan G. has helped us to find and fix some issues on web sites we're protecting. This kind of help is greatly appreciated from a security perspective. This way we can improve ourselves and protect our customers. Thanks again in my name.
    6 December, 2019
     r0m01736939:
Thank you for your report. I was able to fix it quickly :)