The Best Technology Platform in Cannabis.
| Target | Type | Severity |
|---|---|---|
https://store.sweedpos.com/* Copy | Web | Critical |
https://curaleaf.sweedpos.com/* Copy | Web | Critical |
https://prime.sweedpos.com/l* Copy | Web | Critical |
https://demo.sweedpos.com/* Copy | Web | Medium |
https://sales.sweedpos.com/* Copy | Web | Medium |
https://dev.sweedpos.com/* Copy | Web | Low |
https://admin-panel.sweedpos.com/* Copy | Web | Critical |
https://admin-panel.curaleaf.sweedpos.com/* Copy | Web | Critical |
https://admin-panel.prime.sweedpos.com/* Copy | Web | Critical |
https://admin-panel.pilot.sweedpos.com/* Copy | Web | Medium |
https://admin-panel-sales.sweedpos.com/* Copy | Web | Medium |
https://admin-panel-dev.sweedpos.com/* Copy | Web | Low |
https://cashier.sweedpos.com/* Copy | Web | Critical |
https://cashier-prime.sweedpos.com/* Copy | Web | Critical |
https://cashier-curaleaf.sweedpos.com/* Copy | Web | Critical |
https://cashier-demo.sweedpos.com/* Copy | Web | Medium |
https://cashier-sales.sweedpos.com/* Copy | Web | Medium |
https://cashier-dev.sweedpos.com/* Copy | Web | Low |
https://kibana.kube-prod.sweedpos.com/* Copy VPN: YES | Infrastructure | High |
https://kibana.elk.kube.sweedpos.com/* Copy VPN: YES | Infrastructure | Medium |
https://dashboard.kube.sweedpos.com/* Copy VPN: YES | Infrastructure | Critical |
https://dashboard.kube-prod.sweedpos.com/* Copy VPN: YES | Infrastructure | Critical |
https://inner-test3.sweed.app/* Copy | Web | Medium |
VPN: YES
VPN: YES
VPN: YES
VPN: YES
1. Automated Scanning Do not use web application scanners or other automated vulnerability detection tools that generate excessive load or significant traffic.
2. Service Availability Make every effort not to damage or restrict the availability of products, services, or infrastructure during testing.
3. Data Protection Avoid any actions that could compromise personal data, interrupt services, or degrade their performance.
4. Scope Compliance Conduct all research strictly within the defined Scope.
5. Prohibited Methods Do not exploit DoS/DDoS vulnerabilities, perform social engineering attacks, or send spam.
6. Automated Spam Do not use automated scanners to mass-submit forms or create accounts.
7. Vulnerability Chains If you discover a chain of related vulnerabilities, payment will only be made for the vulnerability with the highest severity.
8. Legal Compliance Do not break any laws and always operate within the defined testing boundaries.
9. Confidentiality Do not share details of discovered vulnerabilities with anyone other than the HackenProof Team or authorized employees of the company, unless you have explicit permission.
10. Non-Exploitable or Non-Impactful Issues If a vulnerability is identified but cannot be practically exploited or does not pose a real security threat, no reward will be issued.
11. Duplicate Findings Across Domains If identical vulnerabilities are discovered across different domains within the Scope (e.g., https://demo.sweedpos.com/logout/* and https://sales.sweedpos.com/logout/* ), such reports will be considered duplicates, and only the first valid submission will be rewarded.
We are happy to thank everyone who submits valid reports which help us improve the security. However, only those that meet the following eligibility requirements may receive a monetary reward: