Rewards details:
For each valid vulnerability, the final bounty amount will be discussed and agreed upon with the researcher on a case-by-case basis.
Scope
The following areas of Company’s applications are in scope:
- Web Application:
- User interface/UX functionality
- Data processing and form submissions
- Authentication and session management
Examples of Bugs in Scope:
1. Functional Bugs:
- Incorrect functionality or behavior in core features of the application
- Broken links or missing pages
- Incorrect data displayed in UI (e.g., wrong values in tables, forms, or reports)
- Misalignment of UI elements (e.g., buttons, text fields, images) that impact user experience
- UI components not responding to user interaction as expected (e.g., buttons not clickable, forms not submitting)
2. Compatibility Issues:
- UI inconsistencies across different browsers (e.g., Chrome, Firefox, Safari, Edge) or mobile devices (iOS, Android)
- Broken or misaligned layouts in different screen sizes (responsive design issues)
- Inconsistent or nonfunctional behavior across various operating systems (Windows, macOS, Linux)
3. Usability Issues:
- Poor user experience or unclear navigation flows
- Missing tooltips, help text, or guidance for users
- Confusing labels or error messages that don’t provide sufficient context or instructions
- Inconsistent design patterns or UI elements across different parts of the application
4. Performance Issues:
- Slow page load times or performance bottlenecks
- Unresponsive or laggy UI interactions (e.g., buttons, dropdowns, form submissions)
- Excessive memory usage or CPU consumption that affects the overall performance of the application
5. Regression Bugs:
- Features or functionality that were previously working correctly but are now broken after recent updates or deployments
- Loss of previously expected behavior in existing features or workflows
6. Localization/Internationalization Issues:
- Missing translations or incorrect text display in various languages
- UI text overflow or improper formatting due to varying text lengths in different languages
- Layout issues caused by language-specific characters or text direction (e.g., right-to-left languages like Arabic or Hebrew)
7. Accessibility Issues:
- Missing alt text for images or media files
- Inadequate color contrast for readability
- Keyboard navigation issues (e.g., inability to tab through form fields or buttons)
- Missing or improper ARIA (Accessible Rich Internet Applications) labels and roles
8. Data Handling Bugs:
- Incorrect display of dynamic data (e.g., data fetched from APIs) in the UI
- Data not being saved, updated, or deleted properly in forms or databases
- Data duplication or inconsistency issues across different modules or views
9. Test Coverage Issues:
- Missing test cases for important user flows
- Incomplete or insufficient test coverage for edge cases
- Failing automated tests that should pass according to the expected behavior
Others
- Functional bugs: Broken buttons, incorrect form validations, and non-responsive UI components.
- Core QA issues: Mismatched data between input and output, incomplete transactions, or system errors.
- Extreme test cases: Edge-case scenarios causing failures (e.g., high-volume input or invalid data formats).
Performing Comprehensive Manual Testing for Company’s Web Apps
Execute the Compatibility Testing on below combinations
• Safari & Chrome
• Test Case generation and Providing Report after
Execution
• Performance Testing
Out of Scope
- Security vulnerabilities (these are handled in a separate bug bounty program).
- Suggestions or feature requests.
- Bugs related to third-party integrations not under Company’s control.
- Outdated versions of the app or unsupported devices.