— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for Donorbox Vulnerability Disclosure Project.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"id": "1dcf052a-9cd7-4278-99d1-3c037efbf781",
"name": "Donorbox Vulnerability Disclosure Project",
"company_handle": "donorbox",
"handle": "donorboxvdp",
"url": "https://www.intigriti.com/programs/donorbox/donorboxvdp/detail",
"status": "open",
"confidentiality_level": "public",
"tacRequired": false,
"twoFactorRequired": false,
"min_bounty": {
"value": 0,
"currency": "USD"
},
"max_bounty": {
"value": 0,
"currency": "USD"
},
"targets": {
"in_scope": [
{
"type": "ios",
"endpoint": "https://apps.apple.com/us/app/donorbox-live/id1668808097",
"description": "Donorbox Live is a mobile app that allows orgs to connect Stripe-sanctioned card readers and accept in person payments. See the infrastructure section below for details.",
"impact": "No Bounty"
},
{
"type": "url",
"endpoint": "https://donorbox.org/admin",
"description": "This is the customer support admin console used by Donorbox employees. A donorbox.org account (signed in via Google SSO and with MFA enabled) is required to access this. Additionally, you must be invited to the Rebel Idealist organization in order to gain initial admin access. Please report any unauthorized access to this page.",
"impact": "No Bounty"
},
{
"type": "android",
"endpoint": "https://play.google.com/store/apps/details?id=org.donorbox.cardreader&hl=en&gl=US",
"description": "Donorbox Live is a mobile app that allows orgs to connect Stripe-sanctioned card readers and accept in person payments. See the infrastructure section below for details.",
"impact": "No Bounty"
},
{
"type": "url",
"endpoint": "https://donorbox.org",
"description": "This is the website which includes any page you can navigate to from www.donorbox.org, e.g., www.donorbox.org/pricing.",
"impact": "No Bounty"
},
{
"type": "url",
"endpoint": "https://donorbox.org/embed/potato",
"description": "This is an example of an embed form. Embed forms can be added to a separate website used by the organization. Changing the organization who receives the donation (aka hijacking) or providing fraudulent donations (like a double refund) should not be possible.",
"impact": "No Bounty"
},
{
"type": "url",
"endpoint": "https://donorbox.org/org_admin",
"description": "This is the admin console for organizations. When customers create an org account, they will be directed here to make changes such as creating a campaign, connecting Stripe or PayPal, and changing the donation form. Donor information and donations can be viewed.",
"impact": "No Bounty"
},
{
"type": "url",
"endpoint": "https://donorbox.org/potato",
"description": "This is an example of a hosted page, which lives under the host domain. Hosted pages are provided for organizations to use as their main website if they don't already have one. When a new donation form is created, a hosted page gets created by default.",
"impact": "No Bounty"
}
],
"out_of_scope": []
}
}— none listed —