EducDesign Bug Bounty Program
General Requirements:
If you believe you've found a security bug on this website, we (EducDesign s.a.) will be happy to work with you to resolve the issue promptly and ensure you are fairly rewarded for your discovery.
Scope:
At this time, the scope of this program is limited ONLY to security vulnerabilities found on the domain
bb.educdesign.luVulnerabilities reported on other properties or applications are currently NOT eligible for monetary reward. High impact vulnerabilities outside of this scope might be considered on a case-by-case basis.
In-Scope Sub-Domain:
bb.educdesign.luTesting Requirements:
- Any vulnerability found should be reported no later than 24 hours after discovery.
- You are not allowed to disclose details about the vulnerability anywhere else.
- You must avoid tests that could cause degradation or interruption of our service.
- You must not leak, manipulate, or destroy any user data.
- You are only allowed to test against accounts you own yourself.
- The use of automated tools or scripted testing is not allowed.
Possible Rewards:
The standard reward is 50€.
To qualify for a reward under this program, you should:
- Be the first to report a vulnerability.
- Include attachments such as screenshots or proof of concept code as necessary.
- Send a clear textual description of the report along with steps to reproduce the vulnerability.
- Disclose the vulnerability report directly and exclusively to us via .
A good bug report should include the following information at a minimum:
- List the URL and any affected parameters
- Describe the browser(s)
- Describe the perceived impact.
- How could the bug potentially be exploited?
- Any video or screenshot can be helpful.
Special Notes:
Our bug bounty program is limited strictly to technical security vulnerabilities of the OLEFA CMS on the website listed in the scope. Any activity that would disrupt, damage or adversely affect any third-party data or account is not allowed.
The following are strictly prohibited:
- Denial of Service attacks.
- Physical attacks against offices and datacenters.
- Social engineering of our service desk, employees or contractors.
- Compromise of EducDesign users or employees account.
- Automated tools or scans, botnet, compromised site, end-clients or any other means of large automated exploitation or use of a tool that generates a significant volume of traffic.
A List of pages on this website you can test: