No reports yet — be the first to share your triage timing for Visma.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
+ added 4 scopes
51d ago
{
"id": "0f95dabb-d299-4574-befc-bb96a3bafb42",
"url": "https://www.intigriti.com/programs/visma/visma/detail",
"name": "Visma",
"handle": "visma",
"status": "open",
"targets": {
"in_scope": [
{
"type": "ios",
"impact": "Tier 2",
"endpoint": "564141518",
"description": "**Visma Scanner**\nVisma Scanner is a mobile app used for sending receipts and invoices to your Visma accounting system.\nThe iOS version of the app can be found here:\nhttps://apps.apple.com/us/app/visma-scanner/id564141518\nPlease read and follow the steps in the Startup guide to create an account and start hacking: https://vismabugbountyprod.z16.web.core.windows.net/VismaScanner-iMXxOpXkhOlTBUQtXfyA-getting-started.pdf\n**Please note that the training code has changed!** It is now: wr0d4 , also make sure to select the same Program/Service options as the Getting Started document has. \n\n**Out of scope:**\n* Session invalidation issues (e.g. logout, password change, email change, role change, user deletion, etc)\n* Private screen exposure in the app\n* Stack traces from api calls\n* Jailbroken devices is out of scope\n* All options for login are out of scope, except eAccounting (please see details in the \"Getting Started instructions document\""
},
{
"type": "url",
"impact": "Tier 2",
"endpoint": "accountsettings.connect.identity.stagaws.visma.com",
"description": "**Connect**\nSee instructions for domain \"connect.identity.stagaws.visma.com\".\n\n**Out of scope:**\n* Session invalidation after enabling 2FA - by design intended to work like this\n* Any other out of scopes on 'connect.identity.stagaws.visma.com'"
},
{
"type": "url",
"impact": "Tier 2",
"endpoint": "admin.stage.vismaonline.com",
"description": "**Visma Online**\nThis is the old interface for the customer's administrators to administrate the company, where we still have some functionality that has not been moved to the new interface. For example invoicing information and everything regarding collaborations with AO. The collaboration part is out of scope as long as the use of student companies.\nPlease read the Getting Started Instructions in the \"myservices.stage.vismaonline.com\" asset description.\n\n**Out of scope:**\n* Session invalidation issues (e.g. logout, password change, email change, role change, user deletion, etc).\n* The collaboration part is out of scope as long as the use of student companies. Collaboration is between Accounting Office and Client. \n\t- This includes using `/Customer/StudentSignup.aspx` to create companies with arbitrary emails\n\t- Please do not target the BB Test Teacher user or any other Teacher users you find, these accounts only exists as a service requirement and disruptions may cause issues with your testing account.\n* Any other out of scopes on 'myservices.stage.vismaonline.com'"
},
{
"type": "url",
"impact": "Tier 2",
"endpoint": "aiassistant.stage.vismaonline.com",
"description": "**AI Assistant**\n\nThe AI Assistant is a AI bot that answers support questions based on public product documentation for Visma Spcs products like Visma eAccounting and Visma Advisor.\n\nYou need to register an user to test this system. The sign-up up process is described in this document:\n\nhttps://vismabugbountyprod.z16.web.core.windows.net/Visma-eAccounting-1GWFyEopW9dTKsGYM3FJ-getting-started.pdf\n**Please note that the training code has changed!** It is now: wr0d4 , also make sure to select the same Program/Service options as the Getting Started document has. \n\nThis video also shows the entire setup (only Swedish audio) https://www.youtube.com/watch?v=kVr_CXgfhi0&t=4s\n\nTLDR: Goto https://admin.stage.vismaonline.com/Customer/StudentSignup.aspx and sign up with the training code \"wr0d4\"\n\n**Out of Scope**\n\n* HTML injection, the AI Assistant should be able to output HTML to the chat window.\n* functionalities that belong to other applications that AI Assistant is integrated with (e.g. Visma Advisor or other Visma SPCS products)."
},
{
"type": "url",
"impact": "Tier 2",
"endpoint": "api.workbox.dk",
"description": "**Dinero**\nThis is Dinero's Public API.See instructions for \"app.workbox.dk\""
},
{
"type": "url",
"impact": "Tier 2",
"endpoint": "app.workbox.dk",
"description": "**Dinero**\nDinero is an accounting software for sole traders and micro businesses based out of Denmark. Our only target group is danish companies and therefore the interface is in danish only. The application is a SaaS application hosted in the cloud and consists of a main application and a number of supportive microservices.\n\nSee the getting started document here: https://vismabugbountyprod.z16.web.core.windows.net/VismaDinero-37UeRwujIXh7r9n3Wol6-getting-started.pdf\n\n**Out of scope:**\n* Issues related to login /user creation / forgot-password and /profile page\n* The Cookie \".AspNet.Cookies\" is not set with HttpOnly which is a known vulnerability - please do not report it.\n* Session invalidation issues (e.g. logout, password change, email change, role change, user deletion, etc).\n* Getting access to Pro features as Free user\n* Rate-limiting issues (accepted risk)\n* cvrservice.workbox.dk, this endpoint is used for searches of publicly available data\n* [2026-03-31] Unauthenticated access to invoice, trade offer, or voucher mailout links — these are intentionally publicly accessible"
},
{
"type": "url",
"impact": "Tier 2",
"endpoint": "authz.workbox.dk",
"description": "**Dinero**\nUsed for Authorization (OAuth). See instructions for \"app.workbox.dk\""
},
{
"type": "android",
"impact": "Tier 2",
"endpoint": "com.visma.blue",
"description": "**Visma Scanner**\nVisma Scanner is a mobile app used for sending receipts and invoices to your Visma accounting system.\nThe Andriod version of the app can be found here:\nhttps://play.google.com/store/apps/details?id=com.visma.blue&hl=en\nPlease read and follow the steps in the Startup guide to create an account and start hacking: https://vismabugbountyprod.z16.web.core.windows.net/VismaScanner-iMXxOpXkhOlTBUQtXfyA-getting-started.pdf\n**Please note that the training code has changed!** It is now: wr0d4 , also make sure to select the same Program/Service options as the Getting Started document has. \n\n**Out of scope:**\n* Session invalidation issues (e.g. logout, password change, email change, role change, user deletion, etc)\n* Private screen exposure in the app\n* Stack traces from api calls\n* Jailbroken devices is out of scope\n* All options for login are out of scope, except eAccounting (please see details in the \"Getting Started instructions document\""
},
{
"type": "url",
"impact": "Tier 2",
"endpoint": "connect.identity.stagaws.visma.com",
"description": "**Connect**\nVisma Connect is featurewise a small but critical component in the Visma portfolio. It is a single sign-on solution used by many Visma services. It is also the place where users manage security preferences such as passwords, MFA, 2FA, email and other account settings.\n\nUser accounts for testing can be created on https://connect.identity.stagaws.visma.com (this signup flow is not available in production).\n\nThe test accounts will not have access to any other services right now, so testing is limited to the login portal itself.\n\n**Out of scope:**\n* Session invalidation after enabling 2FA - by design intended to work like this.\n* Please do not knowingly target the BB Test Teacher user or any other users that you have not created yourself."
},
{
"type": "url",
"impact": "Tier 2",
"endpoint": "eaccounting.stage.vismaonline.com",
"description": "**eAccounting**\nThis is \"Visma eAccounting\" (aka Visma eEkonomi / Visma ePasseli) which is an ERP system available in Sweden, Norway, Finland and The Netherlands.\n\nWe've added into scope also the eEkonomi \"Visma Lön Smart\" which is a subservice of eAccounting. This can be found after you activate your account (check out the instructions bellow).\n\nYou can read more on https://www.visma.no/eaccounting/english/\n\nYou need to register an user to test this system. The sign-up up process is described in this document:\nhttps://vismabugbountyprod.z16.web.core.windows.net/Visma-eAccounting-1GWFyEopW9dTKsGYM3FJ-getting-started.pdf\n**Please note that the training code has changed!** It is now: wr0d4 , also make sure to select the same Program/Service options as the Getting Started document has. \n\nThis video also shows the entire setup (only Swedish audio) https://www.youtube.com/watch?v=kVr_CXgfhi0&t=4s\n\nTLDR: Goto https://admin.stage.vismaonline.com/Customer/StudentSignup.aspx and sign up with the training code \"wr0d4\"\n\n**Out of scope:**\n* Session invalidation issues (e.g. logout, password change, email change, role change, user deletion, etc).\n* Modification of gray-out fields when logged in with an admin account.\n* Improper access control: manipulation of the message conversation by members that have no permission (edit subject, join thread conversation, closing the conversation).\n* Email phishing\n* PDF injection\n* Permissions for Lön Smart (the permissions in eAccounting don´t apply at all for Lön Smart).\n* Possibility to create Orders and Quotes with amount 0€\n* Race Condition in article stock limits\n\n* We plan to fix all server-side validation for all tabs mentioned below. All these are under Lön Smart in eAccounting. So until all fixes are applied the following will remain out of scope:\n\t- Fix server-side validation for tab Basic Information on Employee\n\t- Fix server-side validation for tab Employment on Employee\n\t- Fix server-side validation for tab Pay on Employee\n\t- Fix server-side validation for tab Taxes on Employee\n\t- Fix server-side validation for tab Holiday on Employee\n\t- Fix server-side validation for tab Reporting on Employee\n\t- Fix server-side validation for tab Payslip on Employee\n\t- Fix server-side validation for tab Input values on Employee\n\t- Fix server-side validation for tab Pay and payments in payroll settings\n\t- Fix server-side validation for tab Holiday in payroll settings\n\t- Fix server-side validation for tab Accounting in payroll settings\n\t- Fix server-side validation for tab Work schedules in payroll settings\n\t- Fix server-side validation for tab Agreements in payroll settings\n\t- Fix server-side validation for tab Paycodes in payroll settings\n\t- Fix server-side validation for tab Shortcuts in payroll settings"
},
{
"type": "url",
"impact": "Tier 2",
"endpoint": "eaccountingprinting.stage.vismaonline.com",
"description": "**eAccounting**\nYou reach this asset by creating and viewing a report under the Accounting/Reports menu as a logged on user in asset \"eaccounting.stage.vismaonline.com\""
},
{
"type": "url",
"impact": "Tier 2",
"endpoint": "identity.stage.vismaonline.com",
"description": "**Visma Online**\nVisma Connect is used as identity provider, but an own identity server is used to provide JWT tokens that are used by MyServices (and others). \nPlease read the Getting Started instructions document in the \"myservices.stage.vismaonline.com\" asset description.\n\n**Out of scope:**\n* Session invalidation issues (e.g. logout, password change, email change, role change, user deletion, etc).\n* Please do not target the BB Test Teacher user or any other Teacher users you find, these accounts exists as a service requirement and disruptions may cause issues with your testing account and will not be considered as higher impact."
},
{
"type": "url",
"impact": "Tier 2",
"endpoint": "myservices-api.stage.vismaonline.com",
"description": "**Visma Online**\nThis is the API behind \"myservices.stage.vismaonline.com\".\nPlease read the Getting Started instructions document in the asset description \"myservices.stage.vismaonline.com\"."
},
{
"type": "url",
"impact": "Tier 2",
"endpoint": "myservices.stage.vismaonline.com",
"description": "**Visma Online**\nThis is an interface where the customer's users can access all their services, and customer's administrators can manage users on the company and manage users' access to services that the company has. \nMore information about the service and test accounts creation can be found here: \nhttps://vismabugbountyprod.z16.web.core.windows.net/VismaOnline-9Jn9Xh382zaQsQ8IqT2x-getting-started.pdf\n**Please note that the training code has changed!** It is now: wr0d4 , also make sure to select the same Program/Service options as the Getting Started document shows. \n\n\n**Out of scope:**\n* Please **do not** target the BB Test Teacher user or any other Teacher users you find during sign-up as this would violate our Program Rules. If you need to test cross-account issues please create a 2nd test user yourself.\n* Generating support codes for another tenant (grants read-only access for support), only report if you've found a way to exploit the code without support staff involvement. \n* Session invalidation issues (e.g. logout, password change, email change, role change, user deletion, etc)."
},
{
"type": "url",
"impact": "Tier 2",
"endpoint": "oauth.developers.stagaws.visma.com",
"description": "**Visma Developer Portal**\nVisma Developer Portal is used both internally and externally by developers for registering OAuth 2.0/OpenID Connect applications for Single-Sign-On with Visma (Visma Connect) and/or API integration.\n\nExisting Visma Connect users accounts can be used for testing. We also allow registration of new users if needed.\n\nUsers need to register an organization as part of the sign-in or to be added (invite) to an existing organization by organization's manager. The user which registers the organization also gets manager role assigned.\n\nEach organization has its own set of OAuth 2.0/OpenID Connect applications.\n\nPlease read the Getting Started Instructions here: https://vismabugbountyprod.z16.web.core.windows.net/VismaDeveloperPortal-Ze8WD6GFaIFdLvE2ekbN-getting-started.pdf\n\n\n\n**Out of scope:**\n* session invalidation across browsers/devices - this is how it is intended to work by design\n* issues related to other APIs except DevPortal Bug Bounty Interactive and DevPortal Bug Bounty Non-Interactive"
},
{
"type": "url",
"impact": "Tier 2",
"endpoint": "photoservice.stage.vismaonline.com",
"description": "**Visma Scanner**\n\nBackend service for Visma Scanner mobile app, see instructions for domain \"com.visma.blue\" or “564141518”"
},
{
"type": "url",
"impact": "Tier 2",
"endpoint": "ai-testing.maventa.com",
"description": "**Visma AutoInvoice/Maventa**\nThis is the main UI for Visma AutoInvoice. AutoInvoice is Visma's automated and fully ERP integrated service for sending, receiving and handling invoices. AutoInvoice converts and exchanges electronic invoices, optionally prints invoices that can't be sent electronically, receives and interpret PDF invoices and offers services for scanning and interpretation of paper invoices. AutoInvoice handles both Business to Business (B2B) and Business to Consumer (B2C) invoices.\n\nUses partially the embeddable user interface from `autointerface-embeddable-stage.maventa.com`\n\nCreate a test account on https://ai-testing.maventa.com/registrations, or use one of the demo accounts in the getting started instructions below:\nhttps://vismabugbountyprod.z16.web.core.windows.net/VismaAutoinvoice-tHNjPCTbrmGiPY5y0xr8-getting-started.pdf\n\n \n\n**Out of scope or works as expected (accepted risk):**\n* adding users to your own company without consent\n* changing other user's notification settings as company admin\n* language change CSRF\n* application level DOS from /gdpr endpoint\n* duplicate BID/organization number check on registration can be circumvented by race condition (e.g. open two accounts with same BID/org number at same time)\n* IDOR to delete Invoice ID's belonging to different companies by using GDPR removal form (background job checks the right to delete invoices)\n* Hyperlink Injection via emails while adding users to your company\n* User Enumeration via Timing Discrepancy while registering new users\n* Logout CSRF\n* Customer service/chatbot (these are a 3rd party service)\n* Note! ai-testing.maventa.com and testing.maventa.com point to the same application but have different branding on the UI. Authentication to the user interface is handled using the Visma Connect service."
},
{
"type": "url",
"impact": "Tier 2",
"endpoint": "ax-stage.maventa.com",
"description": "**Visma AutoInvoice/Maventa**\nhttps://ax-stage.maventa.com is a REST API connected to Visma AutoInvoice.\n\nAPI documentation is available on https://documentation.maventa.com/rest-api/ and https://ax-stage.maventa.com/swagger/#/\n\nSee instructions for domain `ai-testing.maventa.com` to get user credentials.\n\n**Out of scope or works as expected (accepted risk):**\n* Regular users are allowed to read certain company settings even though they are not perhaps visible in the UI (but they are not allowed to edit the settings)\n* Adding users to your own company without consent\n* Changing other user's notification settings as company admin"
},
{
"type": "url",
"impact": "Tier 2",
"endpoint": "autointerface.stag.visma.net",
"description": "**Visma AutoInvoice/Maventa**\nSee instructions for domain 'ai-testing.maventa.com' to get user credentials.\n\nThe same resource can be accessed through the URL autointerface-embeddable-stage.maventa.com\n\nAll data processing is done through the REST API at ax-stage.maventa.com\n\n**Out of scope or works as expected (accepted risk):**\n* Clickjacking is out of scope for this asset since it is designed to be framed (embedded) in other 3rd party services.\n* Regular users are allowed to view certain admin settings pages (but not allowed to edit the settings)\n* Permissive CORS on the embeddable UI. The component is designed to be embedded by third-party integrators from unknown/arbitrary origins, so cross-origin access is intentional and out of scope"
},
{
"type": "url",
"impact": "Tier 2",
"endpoint": "testing.maventa.com",
"description": "**Visma AutoInvoice/Maventa**\t\nhttps://testing.maventa.com/apis/v1.1/wsdl is a SOAP API connected to Visma AutoInvoice.\n\nAPI documentation is available on https://documentation.maventa.com/soap-api/\n\nSee instructions for domain 'ai-testing.maventa.com' to get user credentials."
}
],
"out_of_scope": []
},
"max_bounty": {
"value": 7500,
"currency": "EUR"
},
"min_bounty": {
"value": 100,
"currency": "EUR"
},
"tacRequired": false,
"company_handle": "visma",
"twoFactorRequired": false,
"confidentiality_level": "public"
}aiassistant.stage.vismaonline.com· Tier 2564141518· Tier 2— none listed —
first indexed
56d ago · 16 in-scope assets