Santé publique France is the national public health agency.
Created in May 2016 by ordinance and decree, it is a public administrative establishment under the supervision of the Ministry of Health. Our mission: to improve and protect the health of populations. This mission revolves around three major axes: anticipate, understand and act.
This program concerns all the public sites of Santé publique France with a strong image risk.
The scopes of our programs are detailed further below, but here is a quick explanation of the services available on the urls listed :
For the health prevention platform Mangerbouger, you can create accounts with @yeswehack.ninja https://yeswehack.com/user/tools/email-alias
For the health prevention platform TabacInfoService, you can create accounts with @yeswehack.ninja https://yeswehack.com/user/tools/email-alias
We believe that no technology is perfect and that working with skilled security researchers is crucial in identifying weaknesses in our technology.
If you believe you've found a security bug in our service, we are happy to work with you to resolve the issue promptly and ensure you are fairly rewarded for your discovery.
Any type of denial-of-service attacks is strictly forbidden, as well as any interference with network equipment and our infrastructure.
We are happy to thank everyone who submits valid reports which help us improve the security of Santé publique France however, only those that meet the following eligibility requirements may receive a monetary reward:
In the context of this program, we do not intend to encourage, accept or reward reports of leaks that are not applicable to our program’s scope and identified outside of our program’s scope, such as:
Also, in order not to encourage dark and grey economies, in particular the purchase, resale and trade of identifiers or stolen information, as well as all types of dangerous behaviour (e.g. social engineering, ...), we will not accept or reward any report based on information whose source is not the result of failure on the part of our organization or one of our employees/service providers.
This excludes, but is not limited to:
To summarize our policy, you may refer to this table :
Source of leak is in-scope | Source of leak belongs to our organization but is out-of-scope | Source of leak does not belong to our organization and is out-of-scope | |
---|---|---|---|
Impact is in-scope (e.g. valid credentials on an in-scope asset) | Eligible | Eligible | Not Eligible |
Impact is out-of-scope (e.g. valid credentials for an out-of-scope asset) | Eligible | Not Eligible | Not Eligible |
Scope Type | Scope Name |
---|---|
api | sso.mangerbouger.fr |
web_application | www.onsexprime.fr |
web_application | www.1000-premiers-jours.fr |
web_application | mangerbouger.fr |
web_application | questionsexualite.fr |
web_application | vaccination-info-service.fr |
web_application | professionnels.vaccination-info-service.fr |
web_application | www.vivre-avec-la-chaleur.fr |
web_application | www.tabac-info-service.fr |
Scope Type | Scope Name |
---|---|
undefined | Domains not listed in scope are by default all out of scope |
This policy crawled by Onyphe on the 2025-04-14 is sorted as bounty.
FireBounty © 2015-2025