Let us introduce you to Swapcard.
Swapcard is a platform for event organizers to engage their audiences. Connect attendees and boost exhibitors ROI.
Swapcard is working with worldwide events including events on Security, Government event, Health topics, etc.
Swapcard appreciates the effort of software security researchers who work to make the Internet more secure. We are here to reward the work of security researchers who find issues within our web services and apps.
If you have questions about our bug bounty program or are unable to properly access/test an in-scope asset please email security@swapcard[.]com.
We don't have that many rules, we want you to be the most creative as possible, and report us vulnerabilities that will make us ?
The only rules are :
All bug reports should include the following information to be considered for a bounty.
Screenshots or videos of the vulnerability are highly encouraged and will result in quicker treatment ?
You can find our latest feature release description page here: https://www.notion.so/swapcard/Last-releases-94ded507e7d240ccb25f5474aa78fbbc
With our form builder, you’ll be able to customize the registration process with the fields of your choice, set what is required, and add as many pages as needed.
You’ll be able to make multiple tickets if you choose. Each ticket can have a limited or unlimited quantity. You can also assign a Swapcard group to each ticket type. With this option, you can control the permissions within the Swapcard event from the moment they register.
You can retrieve the custom URL using the new 3-dot menu on the ticket listing or get it directly from the ticket details view.
Registrations can be managed cohesively with the current attendees. You’ll be able to add registrations, modify tickets, and even cancel registrations.
Setting up 2-Step Authentication
Here's a brief overview of how it works:
Note to hunters:
Scope Type | Scope Name |
---|---|
android_application | https://play.google.com/store/apps/details?id=com.swapcard.apps.android&hl=fr |
api | api.swapcard.com |
api | chat-api.swapcard.com/graphql |
api | developer.swapcard.com/event-admin/graphql |
api | login.swapcard.com |
api | img.swapcard.com |
api | t.swapcard.com |
api | studio-api.swapcard.com |
ios_application | https://apps.apple.com/fr/app/swapcard/id879488719 |
web_application | app.swapcard.com |
web_application | studio.swapcard.com |
web_application | team.swapcard.com |
Scope Type | Scope Name |
---|---|
undefined | By default all the endpoints that are not listed in the allowed scopes are out of scope of the program. |
web_application | *dev.swapcard.com |
web_application | page.swapcard.com |
web_application | blog.swapcard.com (Hubspot) |
web_application | aide.swapcard.com (Zoho) |
web_application | help.swapcard.com (Zoho) |
web_application | books.swapcard.com (Zoho) |
web_application | l.swapcard.com |
web_application | c.swapcard.com |
web_application | sentry.swapcard.com (Except if you notice a miss-configuration) |
web_application | survey.swapcard.com |
web_application | www.swapcard.com (static corporate website) |
This program crawled on the 2022-11-16 is sorted as bounty.
FireBounty © 2015-2025