Bug Bounties

phpBB

Powered by: 

Allows bounty splitting: 

Average time to first program response: 44

Average time to bounty awarded null: 

Average time to report resolved: 

Handle phpbb

Managed program: false

Name: phpBB

Offers bounties: false

Offers swag: false

Response efficiency percentage: 100

Submission state: open

Url: https://hackerone.com/phpbb

Website: https://www.phpbb.com

In scope:

  • Asset identifier: https://github.com/phpbb/phpbb
  • Asset type: SOURCE_CODE
  • Availability requirement: high
  • Confidentiality requirement: high
  • Eligible for bounty: 
  • Eligible for submissions: true
  • Instruction: The Admin Control Panel allows adminstrators to create custom BBcodes. This feature also allows the use of JavaScript, therefore XSS created by an adminstrator is out of scope.
  • Integrity requirements: high
  • Max severity: critical