I reported it on HackerOne, it was only after I refused to post it on their free program that they added me to their paid private one.
It was marked as "medium", I got $250 for it.
I reported it on HackerOne, it was only after I refused to post it on their free program that they added me to their paid private one.
It was marked as "medium", I got $250 for it.
https://www.first.org/cvss/calculator/3.0#CVSS:3.0/AV:N/AC:L...
But I think how private that data is to the end user should also be taken into account. It’s a medium for technical risk (relative to server remote exec), but it should be seen as a high priority for the company and rewarded as such.
If an end user were to ask that company “why did you leak all my private data” their response would be “your data is worth less than $250 in human labour and is seen as a medium security risk”?
CVSS scores are put into audit reports --- at the ouiji levels clients want --- to shut up the suits in compliance.
I'm not aware of any programs on HackerOne that don't follow this practice, so it's not "super uncommon".
I modified the assumptions that were made by the reporter and came out with Low.
This is one example of why this is a nonsense metric.
Compared with hiring a pen testing team, offering high bounties seems like a bargain as you get actual exploits that would impact the company.
I have, uh, some experience with the rates here.
"XSS bug in a popular note taking app ... attacker to download all the users notes just by having them visit a URL"
So as to not feel worried that future vulnerabilities would get sold on the black market instead
Interesting to hear,
Makes me think that there is not any big marked for exploits targeting smaller companies. Maybe such exploits (for smaller products) would be useful primarily for spear phishing? and not bring in so much money if sold, & hard to find a buyer?
Still, if the note taking app was sth well known like Ev*rnote, I wish they'd pay more. (No idea if it was.)