52235 policies in database
Link to program      
2016-12-21
2020-01-30
Mastercard logo
Thank
Gift
HOF
Reward

Reward

100 $ 

Mastercard

Have thoughts on how this program could be improved? Please provide your feedback to Bugcrowd and Mastercard!

Mastercard is a technology company in the global payments industry. We operate the world’s fastest payments processing network, connecting consumers, financial institutions, merchants, governments and businesses in more than 210 countries and territories. Mastercard products and solutions make everyday commerce activities – such as shopping, traveling, running a business and managing finances – easier, more secure and more efficient for everyone. For nearly half a century, Mastercard has been a leader in safety and security. As payment methods continue to evolve, Mastercard is committed to advancing digital security, which includes rigorous testing for potential vulnerabilities. You can help us make our products and services even safer and earn rewards by reporting potential vulnerabilities.

A Couple Important Requirements for Mastercard:

  • When submitting a report to Mastercard, please be sure to include your IP address that you were testing from somewhere in your report. It is greatly helpful to MasterCard.
  • Due to GDPR and legal requirements. All testing must be conducted using your @bugcrowdninja.com email ID only. If you fail to use your @Bugcrowdninja.com email ID, you run the risk of getting blocked from accessing Mastercard applications.

Rewards

Rewards will be facilitated through Payoneer ONLY (Setup payment methods)

For the initial prioritization/rating of findings, this program will use the Bugcrowd Vulnerability Rating Taxonomy. However, it is important to note that in some cases a vulnerability priority will be modified due to its likelihood or impact. In any instance where an issue is downgraded, a full, detailed explanation will be provided to the researcher - along with the opportunity to appeal, and make a case for a higher priority.

Use of automated scanners and tools to find vulnerabilities is strictly not allowed. Mastercard requests that testers do not perform automated/scripted testing of web forms, especially "Contact Us" forms that are designed for customers to contact the Support team.

Scope and rewards

Program rules

This program follows Bugcrowd’s standard disclosure terms.

For any testing issues (such as broken credentials, inaccessible application, or Bugcrowd Ninja email problems), please email support@bugcrowd.com. We will address your issue as soon as possible.

This program does not offer financial or point-based rewards for P5 — Informational findings. Learn more about Bugcrowd’s VRT.

In Scope

Scope Type Scope Name
undefined

MasterCard.us - www.mastercard.us/en-us.html

undefined

MasterCard.ch - (German) - www.mastercard.ch/de-ch.html

undefined

MasterCard.ch - (French) - www.mastercard.ch/fr-ch.html

undefined

MasterCard.ru - www.mastercard.ru/ru-ru.html

undefined

MasterCard.com.au - www.mastercard.com.au/en-au.html

undefined

MasterCard.nl - www.mastercard.nl/nl-nl.html

web_application

Simplify Commerce - www.simplify.com/commerce/

web_application

https://developer.mastercard.com

web_application

donate.mastercard.com

Out of Scope

Scope Type Scope Name
api

All Available Mastercard Developer APIs

undefined

Core Priceless.com - demo.priceless.com

web_application

demo.priceless.com/golf

web_application

demo.priceless.com/travel

web_application

demo.priceless.com/standup

web_application

Order placement on demo.priceless.com


This program have been found on Bugcrowd on 2016-12-21.

FireBounty © 2015-2024

Legal notices | Privacy policy