— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for CM.com.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"id": "efd8bd86-a986-4b4a-9eda-c9a6a1a6b540",
"name": "CM.com",
"company_handle": "cmcom",
"handle": "cmcom",
"url": "https://www.intigriti.com/programs/cmcom/cmcom/detail",
"status": "open",
"confidentiality_level": "public",
"tacRequired": false,
"twoFactorRequired": false,
"min_bounty": {
"value": 5,
"currency": "EUR"
},
"max_bounty": {
"value": 2625,
"currency": "EUR"
},
"targets": {
"in_scope": [
{
"type": "url",
"endpoint": "login.cm.com",
"description": null,
"impact": "Tier 1"
},
{
"type": "wildcard",
"endpoint": "*.ticketing.cm.com",
"description": "Login to your account and go to https://www.cm.com/en-gb/app/ticketing/\nFrom here you can create tickets and much more!\nMake sure to take a look at the user-side ticket store as well (https://store.ticketing.cm.com/..)\nWant to test a shop? Please don't use our live customer shops but instead use https://shop.ticketing.cm.com/intigriti-pentest-shop/",
"impact": "Tier 2"
},
{
"type": "url",
"endpoint": "api.cm.com",
"description": null,
"impact": "Tier 2"
},
{
"type": "url",
"endpoint": "api.cmtelecom.com",
"description": "Some of the applications that are in our scope use our old api. \nIf you find a bug on this api and it is from a product that is in scope, it is valid.",
"impact": "Tier 2"
},
{
"type": "wildcard",
"endpoint": "cm.com/[locale]/app/*",
"description": null,
"impact": "Tier 2"
},
{
"type": "url",
"endpoint": "cm.com/[locale]/register",
"description": null,
"impact": "Tier 2"
},
{
"type": "url",
"endpoint": "appmiral.com",
"description": null,
"impact": "Tier 3"
},
{
"type": "url",
"endpoint": "building-blocks.com",
"description": null,
"impact": "Tier 3"
},
{
"type": "url",
"endpoint": "cm.com/app/messagingtrial/",
"description": "An application that makes it possible for developers to do a limited test of sending messages using the CM.COM business messaging API.\n\nWhat we would like to know is:\n* Can the application be exploited to allow sending more than the allowed number of messages?\n* Can the app be exploited to send to other recipients besides the whitelisted recipients?",
"impact": "Tier 3"
},
{
"type": "url",
"endpoint": "cmcom.atlassian.net",
"description": "Our Atlassian instance. **In scope for this program are only misconfiguration on our side exposing sensitive data**. Please consider if an issue you find is indeed a configuration issue we made, or if the issue is on Atlassians side (if this is the case, please report it on their bug bounty program!)",
"impact": "Tier 3"
},
{
"type": "other",
"endpoint": "https://github.com/cmdotcom",
"description": "Our public code repositories are being used by our customers. In scope for this domain is issues with the public code we host (vulnerabilities, libraries that have known security concerns, keys accidentally pushed to the public GitHub etc.). \n**Testing the GitHub itself is out-of-scope**, they have their own bug bounty program if you are interested :)",
"impact": "Tier 3"
},
{
"type": "url",
"endpoint": "www.cm.com",
"description": null,
"impact": "Tier 3"
},
{
"type": "wildcard",
"endpoint": "*.appmiral.com",
"description": null,
"impact": "No Bounty"
},
{
"type": "wildcard",
"endpoint": "*.cm.com",
"description": null,
"impact": "No Bounty"
},
{
"type": "wildcard",
"endpoint": "*.cmtelecom.com",
"description": null,
"impact": "No Bounty"
},
{
"type": "ios",
"endpoint": "1199521324",
"description": "Right now we don't have a way to make test accounts for these apps, this will be added in the future",
"impact": "No Bounty"
},
{
"type": "ios",
"endpoint": "1579530451",
"description": "Right now we don't have a way to make test accounts for these apps, this will be added in the future",
"impact": "No Bounty"
},
{
"type": "android",
"endpoint": "com.cm.cashregister",
"description": "Right now we don't have a way to make test accounts for these apps, this will be added in the future",
"impact": "No Bounty"
},
{
"type": "android",
"endpoint": "com.ticketflow.ticketscanner",
"description": "Right now we don't have a way to make test accounts for these apps, this will be added in the future",
"impact": "No Bounty"
},
{
"type": "wildcard",
"endpoint": "demo.globalticket.com/*",
"description": "GlobalTicket is one of our integrations. \nBe sure to check out `/cms` to try and work your way into it.",
"impact": "No Bounty"
}
],
"out_of_scope": []
}
}*.appmiral.com1199521324· No Bounty1579530451· No Bounty— none listed —