At Salt, we believe in teamwork. Together we achieve more.
That's why we value your feedback, as it enables us to continuously improve our service. If you have found a weakness in our service, please contact us so that we can rectify the problem and you can be assured of fair compensation for your discovery.
Thank you in advance for your loyal cooperation and contribution to making Salt better day by day.
May the show go on.
Please adhere to the following rules while performing research on this program:
We are happy to thank everyone who submits valid reports which help us improve the security of Salt Mobile SA, however only those that meet the following eligibility requirements may receive a monetary reward:
Reward amounts are based on:
Unless you can demonstrate a specific situation where an XSS becomes a "HIGH" or "CRITICAL" finding, it is likely an XSS vulnerability will score as "MEDIUM".
In this case, and if you want your report to be rewarded as a "HIGH" or "CRITICAL" finding, please provide a realistic, proven and step by step detailed scenario of exploitability, including elements that could be modified through this exploit, or actions that could be undertaken on behalf of targeted user.
For example : XHR request to modify account information and could lead to an account take over.
There is also a certain chance, that similar XSS exploits on different endpoints or parameters are caused by the same underlying input validation weakness. If that is the case, we reserve the right to honor only a single report and to reject the other ones as "Duplicate" or "Informative".
The use of N-Day exploit is only considered valid after the patch has been available for at least two months.
Scope Type | Scope Name |
---|---|
web_application | https://my.salt.ch |
web_application | https://eshop.salt.ch |
web_application | https://login.salt.ch |
Scope Type | Scope Name |
---|---|
undefined | All domains or subdomains not listed in the above list of 'Scopes' |
This program crawled on the 2023-05-24 is sorted as bounty.
FireBounty © 2015-2025