Powered by: Allows bounty splitting:
Average time to first program response: 44
Average time to bounty awarded null:
Average time to report resolved:
Handle phpbb
Managed program: false
Name: phpBB
Offers bounties: false
Offers swag: false
Response efficiency percentage: 100
Submission state: open
Url: https://hackerone.com/phpbb
Website: https://www.phpbb.com
In scope: Asset identifier: https://github.com/phpbb/phpbbAsset type: SOURCE_CODEAvailability requirement: highConfidentiality requirement: highEligible for bounty: Eligible for submissions: trueInstruction: The Admin Control Panel allows adminstrators to create custom BBcodes. This feature also allows the use of JavaScript, therefore XSS created by an adminstrator is out of scope.Integrity requirements: highMax severity: critical