Due to an increased volume of invalid reports, we are temporarily suspending our bug bounty program. All reports submitted prior to November 13, 2024, will be reviewed and compensated in accordance with the original agreement.
Please team for further information.
The program covers our corporate website www.cdn77.com and our customer portal client.cdn77.com.
The primary focus is on identifying and mitigating critical security vulnerabilities, such as:
Certain areas are out of scope. The testing of any vulnerabilities outside the defined scope is strictly prohibited and will result in disqualification from eligibility for legal safe harbor protections.
The following issues are out of scope and will not be considered as security vulnerabilities:
The reward structure for this program is based on the severity of the reported vulnerability, the potential impact, and the ease of exploitation. We utilize Bugcrowd’s Vulnerability Rating Taxonomy as a general guideline for rating and categorizing vulnerabilities. However, this taxonomy is intended as a reference only, and we reserve the right to decline certain reports if the identified issue is not significant within our specific context. If any vulnerabilities are stated in these Program Terms as out of scope while being categorized as a vulnerability in Bugcrowd’s Vulnerability Rating Taxonomy, the Program Terms take precedence.
We reserve the right to adjust bounty awards based on the proven impact of the vulnerability. This ensures that reports demonstrating a significant, real-world effect will be compensated accordingly, while reports identifying issues without measurable impact or without relevance to our specific context may receive lower compensation or no reward.
Technical severity | Reward |
---|---|
P1 | $2,000 - $3,000 |
P2 | $1,000 - $2,000 |
P3 | $500 - $1,000 |
P4 | $250 - $500 |
P5 | $100 - $250 |