[{"id":3778983,"new_policy":"As DSM GRUP DANIŞMANLIK İLETİŞİM VE TİCARET A.Ş. (“DSM”), we highly value security and privacy and look forward to working with the security community to find security vulnerabilities in order to keep our businesses and customers safe. Off the back of a successful HackerOne Challenge, we are excited to continue leveraging Hacker Powered Security with HackerOne's diverse talent pool.\n\n# Response Targets\nDSM will make its best effort to meet the following SLAs for hackers participating in our program:\n\n| Type of Response | SLA in business days |\n| --- | --- |\n| **First Response** | 2 days |\n| **Time to Triage** | 2 days |\n| **Time to Bounty** | 14 days |\n| **Time to Resolution** | Depends on severity and complexity |\n\nWe will make every effort to keep you informed of our progress throughout the remediation process.\n\n# Scope\nOur core target assets are listed in the table below. \n\n\u003e **Note:** For all Web / API targets, API calls initiated from both web and mobile applications are explicitly accepted in scope.\n\n| Asset / Application        | Platform             | Identifier / URL                                                                                       |\n| ------------------------- | ------------------- | ----------------------------------------------------------------------------------------------------- |\n| Trendyol                   | Web / API            | www.trendyol.com                                                                                       |\n| Dolap                      | Web / API            | www.dolap.com                                                                                          |\n| Trendyol Milla             | Web / API            | www.trendyol-milla.com                                                                                 |\n| Trendyol Go Yemek          | Web / API            | www.tgoyemek.com                                                                                       |\n| Trendyol Application       | Android (Play Store) | [trendyol.com](https://play.google.com/store/apps/details?id=trendyol.com)                             |\n| Trendyol Milla Application | Android (Play Store) | [com.trendyol.milla.android](https://play.google.com/store/apps/details?id=com.trendyol.milla.android) |\n| Trendyol Go Application    | Android (Play Store) | [com.trendyol.go](https://play.google.com/store/apps/details?id=com.trendyol.go)                       |\n| Dolap Application          | Android (Play Store) | [com.dolap.android](https://play.google.com/store/apps/details?id=com.dolap.android)                   |\n| Trendyol Milla Application | iOS (App Store)      | [6467634418](https://apps.apple.com/us/app/trendyolmilla/id6467634418)                                 |\n| Trendyol Application       | iOS (App Store)      | [524362642](https://apps.apple.com/tr/app/trendyol-online-al%C4%B1%C5%9Fveri%C5%9F/id524362642)        |\n| Dolap Application          | iOS (App Store)      | [1127881507](https://apps.apple.com/us/app/dolap-i-kinci-el-al%C4%B1%C5%9Fveri%C5%9F/id1127881507)     |\n\n# Test Plan\nWeb traffic to and from DSM properties produces petabytes of data every day. To ensure your testing is identified correctly and our SOC team does not block your research activity, please follow these instructions:\n\n- **Accounts:** Please create accounts using your `username@wearehackerone.com` email address. Some of our properties will require this to be eligible for a bounty.\n- **Custom Header:** You must include the following custom HTTP header in all your traffic:\n  `X-Bug-Bounty: hackerone-{username}`\n\n# Program Rules\nWe expect researchers to adhere to the \"Do No Harm\" principle. In the event of a violation, you may face exclusion from the program:\n\n- **Focus on Impact:** We evaluate reports based on the highest plausible business impact. Show us the worst-case scenario, but do not cross the line into data destruction.\n- **Chaining \u0026 Post-Exploitation:** Chaining vulnerabilities is encouraged to demonstrate impact. However, if you compromise a server or internal system, **stop immediately**. Do not attempt to pivot, port scan internal networks, or escalate privileges further.\n- Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.\n- Submit one vulnerability per report, unless chaining is required.\n- Do not compromise or test DSM accounts that are not your own.\n- Do not threaten DSM, engage in extortion, or demand ransom. \n- Do not perform brute force, DoS attacks, or any actions that degrade DSM services.\n- Social engineering (e.g., phishing, vishing) and physical attacks against DSM facilities are strictly prohibited.\n- Employees, contractors, and their immediate families are prohibited from participating.\n\n# Out-of-Scope Vulnerabilities \u0026 Exclusions\nWhen reporting vulnerabilities, please consider the realistic attack scenario/exploitability, and the technical security impact of the bug. The following issues and testing methods are explicitly excluded from this program:\n\n**1. Excluded Assets \u0026 Features**\n* Any non-DSM applications, third-party integrations, or external hostings.\n* Submitting domain takeovers. We accept notifications of domain takeover for security purposes, but they are not eligible for financial rewards. *Please note that performing the actual takeover of the asset is strictly prohibited.*\n* 0-day vulnerabilities: 0-day and other CVE vulnerabilities may be reported 45 days after initial publication.\n\n**2. Prohibited Testing Methods**\n* **Denial of Service:** Any activity that could lead to the disruption of our service (DoS/DDoS).\n* **Automated Testing:** Running high-frequency automated scans, scanner outputs, and bugs found purely via generic automated tools without manual verification.\n* **Brute Force:** Any form of credential, token, or identifier brute forcing.\n* **Social Engineering:** Any form of social engineering attacks (e.g., phishing, vishing, smishing) targeted at DSM personnel, customer support, or customers.\n* **Physical Attacks:** Conducting any kind of physical attack on DSM’s personnel, office properties, logistics infrastructure, or data centers.\n* **Data Exfiltration:** Exfiltrating production or customer data. Please test only the absolute minimum necessary to validate a proof of concept.\n\n**3. Web Application Exclusions**\n* Clickjacking on pages with no sensitive actions or state-changing functions.\n* Cross-Site Request Forgery (CSRF) on unauthenticated forms, forms with no sensitive actions, or forms with non-impactful business consequences.\n* CORS configurations without a demonstrable, exploitable data-leak scenario.\n* Content spoofing, text injection, or host header injection issues without a significant, proven attack vector (e.g., without being able to modify HTML/CSS dynamically).\n* Open redirects, unless a distinct, secondary security impact can be demonstrated.\n* \"Self\" exploitation vulnerabilities (e.g., Self-XSS, HTML injection affecting only the local session).\n* Flash-based vulnerabilities or legacy Flash-related bugs.\n* Comma Separated Values (CSV) injection without demonstrating a downstream server-side exploit.\n* Form issues regarding missing autocomplete attributes.\n\n**4. Configuration and Defensive Best Practices**\n* Missing security-related HTTP headers (e.g., `X-XSS-Protection`, missing CSP policies) which do not lead directly to a practical vulnerability.\n* Missing `HttpOnly` or `Secure` flags on non-sensitive cookies.\n* Missing email best practices (e.g., invalid, incomplete, or missing SPF/DKIM/DMARC records).\n* Missing best practices in standard SSL/TLS protocol configurations.\n* Software version disclosures, banner grabbing, banner identification issues, descriptive error messages, path disclosures, directory listings, or verbose stack traces without active proof of exploitability.\n* Password complexity guidelines or user enumeration findings.\n* Exposed API keys (e.g., Google Maps API keys) without a demonstrable, high-impact security risk (such as unauthorized write access or sensitive data exposure). Public client-side API keys are not considered sensitive by default.\n\n**5. Environmental \u0026 Client-Side Exclusions**\n* Attacks requiring Man-in-the-Middle (MITM) or prolonged physical access to a user's unlocked device.\n* Vulnerabilities only affecting users of severely outdated or unpatched browsers (defined as being more than 2 stable versions behind the latest released stable browser version).\n* Vulnerabilities relating to root detection, jailbreak status, or certificate pinning on client applications.\n* Vulnerabilities relating to outdated versions of the Android or iOS operating systems.\n* Cloudflare public IP leaks.\n* Previously known vulnerable third-party libraries without a working, contextual Proof of Concept.\n\n# Reporting Requirements\nTo help our triage team validate your findings quickly, all submissions must meet the following baseline requirements. Reports that fail to provide sufficient documentation will be requested to update their report or may be closed as informative.\n\n1. **Clear Summary:** Provide a concise title detailing the vulnerability type and the affected asset/endpoint.\n2. **Detailed Description:** Explain the underlying flaw and how it can be abused.\n3. **Step-by-Step Reproduction Instructions:** Clearly outline the steps required to replicate the vulnerability. Write your steps assuming the reader has no contextual background on your approach.\n4. **Proof of Concept (PoC):** Include explicit PoC material. This can include raw HTTP requests/responses, screenshots, or short screen recordings (MP4 format).\n5. **Impact Evaluation:** Describe the realistic security risk and impact this vulnerability poses to DSM or its customers. Avoid speculative or theoretical harm.\n\n# Disclosure Policy\n* As this is a private program, please do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from DSM.\n* Thank you for joining us in supporting ethical and responsible disclosure. By participating in this program, you agree not to share publicly or privately any details or descriptions of your findings with any third party.\n* Follow HackerOne's standard [disclosure guidelines](https://www.hackerone.com/disclosure-guidelines).\n\n# Confidentiality and Protection of Personal Data\nThe “Confidential Information” shall include, any information provided by DSM to the Hacker (Bug Bounty Program Participants) but not be limited to any information, whether in written, oral, electronic, or other tangible forms including, without limitation, the forms currently available and those made available by new technologies in future, regarding the financial, commercial, technical, professional, market and product-related and all kinds of personal information to be disclosed.\n\nIn principle, DSM does not share personal data with Hacker, and only the Hacker can access personal data based on the legal reason that it is compulsory for the performance of the Articles of Association, limited to the performance of the services provided in the Articles of Association.\n\nIf the Hacker accesses personal data that is not necessary for the performance of the Agreement, it will immediately destroy that information and any copies.\n\nIf you encounter user information that is not your own in the course of your research, please stop and report this activity to our team so we can investigate. Please report to us what information was accessed and delete the data. Do not save, copy, transfer, or otherwise use this data. Continuing to access another person’s data may be regarded as evidence of a lack of good faith.\n\n\n# Safe Harbor\nPlease note that we can only consider your activities to be lawful if they are proportionate and the purpose of your actions is consistent with the purpose of this Policy. We explicitly do not exclude that any attempt to intentionally or grossly negligently attack our systems with the intent to harm us and/or compromise the confidentiality, integrity or availability of our data may be pursued with legal action.\n\n# Legal\nIf reports/notifications falling within the scope of this Policy are conveyed through a different channel, your report/notification will not be taken into consideration by our company. Instead, you will be directed to the BugBounty Program to submit your report. According to our company policies and procedures, reviews of reports and notifications are carried out by our technical teams only when they are transmitted within the scope of the BugBounty program. Therefore, it is necessary to submit your reports through this program.\n\nDSM reserves the right to modify the terms and conditions of this program and your participation in the program constitutes acceptance of all terms. Please check this website regularly as we update our program terms and conditions of participation periodically. We reserve the right to terminate this program at any time.\n\nThank you for keeping DSM and our users safe! \n","has_open_scope":null,"pays_within_one_month":true,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2026-07-24T08:14:35.712Z"},{"id":3776226,"new_policy":"As DSM GRUP DANIŞMANLIK İLETİŞİM VE TİCARET A.Ş. (“DSM”), we highly value security and privacy and look forward to working with the security community to find security vulnerabilities in order to keep our businesses and customers safe. Off the back of a successful HackerOne Challenge, we are excited to continue leveraging Hacker Powered Security with HackerOne's diverse talent pool.\n\n# Response Targets\nDSM will make its best effort to meet the following SLAs for hackers participating in our program:\n\n| Type of Response | SLA in business days |\n| --- | --- |\n| **First Response** | 2 days |\n| **Time to Triage** | 2 days |\n| **Time to Bounty** | 14 days |\n| **Time to Resolution** | Depends on severity and complexity |\n\nWe will make every effort to keep you informed of our progress throughout the remediation process.\n\n# Scope\nOur core target assets are listed in the table below. \n\n\u003e **Note:** For all Web / API targets, API calls initiated from both web and mobile applications are explicitly accepted in scope.\n\n| Asset / Application        | Platform             | Identifier / URL                                                                                       |\n| ------------------------- | ------------------- | ----------------------------------------------------------------------------------------------------- |\n| Trendyol                   | Web / API            | www.trendyol.com                                                                                       |\n| Dolap                      | Web / API            | www.dolap.com                                                                                          |\n| Trendyol Milla             | Web / API            | www.trendyol-milla.com                                                                                 |\n| Trendyol Go Yemek          | Web / API            | www.tgoyemek.com                                                                                       |\n| Trendyol Application       | Android (Play Store) | [trendyol.com](https://play.google.com/store/apps/details?id=trendyol.com)                             |\n| Trendyol Milla Application | Android (Play Store) | [com.trendyol.milla.android](https://play.google.com/store/apps/details?id=com.trendyol.milla.android) |\n| Trendyol Go Application    | Android (Play Store) | [com.trendyol.go](https://play.google.com/store/apps/details?id=com.trendyol.go)                       |\n| Dolap Application          | Android (Play Store) | [com.dolap.android](https://play.google.com/store/apps/details?id=com.dolap.android)                   |\n| Trendyol Milla Application | iOS (App Store)      | [6467634418](https://apps.apple.com/us/app/trendyolmilla/id6467634418)                                 |\n| Trendyol Application       | iOS (App Store)      | [524362642](https://apps.apple.com/tr/app/trendyol-online-al%C4%B1%C5%9Fveri%C5%9F/id524362642)        |\n| Dolap Application          | iOS (App Store)      | [1127881507](https://apps.apple.com/us/app/dolap-i-kinci-el-al%C4%B1%C5%9Fveri%C5%9F/id1127881507)     |\n\n# Test Plan\nWeb traffic to and from DSM properties produces petabytes of data every day. To ensure your testing is identified correctly and our SOC team does not block your research activity, please follow these instructions:\n\n- **Accounts:** Please create accounts using your `username@wearehackerone.com` email address. Some of our properties will require this to be eligible for a bounty.\n- **Custom Header:** You must include the following custom HTTP header in all your traffic:\n  `X-Bug-Bounty: hackerone-{username}`\n\n# Program Rules\nWe expect researchers to adhere to the \"Do No Harm\" principle. In the event of a violation, you may face exclusion from the program:\n\n- **Focus on Impact:** We evaluate reports based on the highest plausible business impact. Show us the worst-case scenario, but do not cross the line into data destruction.\n- **Chaining \u0026 Post-Exploitation:** Chaining vulnerabilities is encouraged to demonstrate impact. However, if you compromise a server or internal system, **stop immediately**. Do not attempt to pivot, port scan internal networks, or escalate privileges further.\n- Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.\n- Submit one vulnerability per report, unless chaining is required.\n- Do not compromise or test DSM accounts that are not your own.\n- Do not threaten DSM, engage in extortion, or demand ransom. \n- Do not perform brute force, DoS attacks, or any actions that degrade DSM services.\n- Social engineering (e.g., phishing, vishing) and physical attacks against DSM facilities are strictly prohibited.\n- Employees, contractors, and their immediate families are prohibited from participating.\n\n# Out-of-Scope Vulnerabilities \u0026 Exclusions\nWhen reporting vulnerabilities, please consider the realistic attack scenario/exploitability, and the technical security impact of the bug. The following issues and testing methods are explicitly excluded from this program:\n\n**1. Excluded Assets \u0026 Features**\n* Any non-DSM applications, third-party integrations, or external hostings.\n* Submitting domain takeovers. We accept notifications of domain takeover for security purposes, but they are not eligible for financial rewards. *Please note that performing the actual takeover of the asset is strictly prohibited.*\n* 0-day vulnerabilities: 0-day and other CVE vulnerabilities may be reported 45 days after initial publication.\n\n**2. Prohibited Testing Methods**\n* **Denial of Service:** Any activity that could lead to the disruption of our service (DoS/DDoS).\n* **Automated Testing:** Running high-frequency automated scans, scanner outputs, and bugs found purely via generic automated tools without manual verification.\n* **Brute Force:** Any form of credential, token, or identifier brute forcing.\n* **Social Engineering:** Any form of social engineering attacks (e.g., phishing, vishing, smishing) targeted at DSM personnel, customer support, or customers.\n* **Physical Attacks:** Conducting any kind of physical attack on DSM’s personnel, office properties, logistics infrastructure, or data centers.\n* **Data Exfiltration:** Exfiltrating production or customer data. Please test only the absolute minimum necessary to validate a proof of concept.\n\n**3. Web Application Exclusions**\n* Clickjacking on pages with no sensitive actions or state-changing functions.\n* Cross-Site Request Forgery (CSRF) on unauthenticated forms, forms with no sensitive actions, or forms with non-impactful business consequences.\n* CORS configurations without a demonstrable, exploitable data-leak scenario.\n* Content spoofing, text injection, or host header injection issues without a significant, proven attack vector (e.g., without being able to modify HTML/CSS dynamically).\n* Open redirects, unless a distinct, secondary security impact can be demonstrated.\n* \"Self\" exploitation vulnerabilities (e.g., Self-XSS, HTML injection affecting only the local session).\n* Flash-based vulnerabilities or legacy Flash-related bugs.\n* Comma Separated Values (CSV) injection without demonstrating a downstream server-side exploit.\n* Form issues regarding missing autocomplete attributes.\n\n**4. Configuration and Defensive Best Practices**\n* Missing security-related HTTP headers (e.g., `X-XSS-Protection`, missing CSP policies) which do not lead directly to a practical vulnerability.\n* Missing `HttpOnly` or `Secure` flags on non-sensitive cookies.\n* Missing email best practices (e.g., invalid, incomplete, or missing SPF/DKIM/DMARC records).\n* Missing best practices in standard SSL/TLS protocol configurations.\n* Software version disclosures, banner grabbing, banner identification issues, descriptive error messages, path disclosures, directory listings, or verbose stack traces without active proof of exploitability.\n* Password complexity guidelines or user enumeration findings.\n\n**5. Environmental \u0026 Client-Side Exclusions**\n* Attacks requiring Man-in-the-Middle (MITM) or prolonged physical access to a user's unlocked device.\n* Vulnerabilities only affecting users of severely outdated or unpatched browsers (defined as being more than 2 stable versions behind the latest released stable browser version).\n* Vulnerabilities relating to root detection, jailbreak status, or certificate pinning on client applications.\n* Vulnerabilities relating to outdated versions of the Android or iOS operating systems.\n* Cloudflare public IP leaks.\n* Previously known vulnerable third-party libraries without a working, contextual Proof of Concept.\n\n# Reporting Requirements\nTo help our triage team validate your findings quickly, all submissions must meet the following baseline requirements. Reports that fail to provide sufficient documentation will be requested to update their report or may be closed as informative.\n\n1. **Clear Summary:** Provide a concise title detailing the vulnerability type and the affected asset/endpoint.\n2. **Detailed Description:** Explain the underlying flaw and how it can be abused.\n3. **Step-by-Step Reproduction Instructions:** Clearly outline the steps required to replicate the vulnerability. Write your steps assuming the reader has no contextual background on your approach.\n4. **Proof of Concept (PoC):** Include explicit PoC material. This can include raw HTTP requests/responses, screenshots, or short screen recordings (MP4 format).\n5. **Impact Evaluation:** Describe the realistic security risk and impact this vulnerability poses to DSM or its customers. Avoid speculative or theoretical harm.\n\n# Disclosure Policy\n* As this is a private program, please do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from DSM.\n* Thank you for joining us in supporting ethical and responsible disclosure. By participating in this program, you agree not to share publicly or privately any details or descriptions of your findings with any third party.\n* Follow HackerOne's standard [disclosure guidelines](https://www.hackerone.com/disclosure-guidelines).\n\n# Confidentiality and Protection of Personal Data\nThe “Confidential Information” shall include, any information provided by DSM to the Hacker (Bug Bounty Program Participants) but not be limited to any information, whether in written, oral, electronic, or other tangible forms including, without limitation, the forms currently available and those made available by new technologies in future, regarding the financial, commercial, technical, professional, market and product-related and all kinds of personal information to be disclosed.\n\nIn principle, DSM does not share personal data with Hacker, and only the Hacker can access personal data based on the legal reason that it is compulsory for the performance of the Articles of Association, limited to the performance of the services provided in the Articles of Association.\n\nIf the Hacker accesses personal data that is not necessary for the performance of the Agreement, it will immediately destroy that information and any copies.\n\nIf you encounter user information that is not your own in the course of your research, please stop and report this activity to our team so we can investigate. Please report to us what information was accessed and delete the data. Do not save, copy, transfer, or otherwise use this data. Continuing to access another person’s data may be regarded as evidence of a lack of good faith.\n\n\n# Safe Harbor\nPlease note that we can only consider your activities to be lawful if they are proportionate and the purpose of your actions is consistent with the purpose of this Policy. We explicitly do not exclude that any attempt to intentionally or grossly negligently attack our systems with the intent to harm us and/or compromise the confidentiality, integrity or availability of our data may be pursued with legal action.\n\n# Legal\nIf reports/notifications falling within the scope of this Policy are conveyed through a different channel, your report/notification will not be taken into consideration by our company. Instead, you will be directed to the BugBounty Program to submit your report. According to our company policies and procedures, reviews of reports and notifications are carried out by our technical teams only when they are transmitted within the scope of the BugBounty program. Therefore, it is necessary to submit your reports through this program.\n\nDSM reserves the right to modify the terms and conditions of this program and your participation in the program constitutes acceptance of all terms. Please check this website regularly as we update our program terms and conditions of participation periodically. We reserve the right to terminate this program at any time.\n\nThank you for keeping DSM and our users safe! \n","has_open_scope":null,"pays_within_one_month":true,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2026-06-19T05:50:37.020Z"},{"id":3776225,"new_policy":"As DSM GRUP DANIŞMANLIK İLETİŞİM VE TİCARET A.Ş. (“DSM”), we highly value security and privacy and look forward to working with the security community to find security vulnerabilities in order to keep our businesses and customers safe. Off the back of a successful HackerOne Challenge, we are excited to continue leveraging Hacker Powered Security with HackerOne's diverse talent pool.\n\n# Response Targets\nDSM will make its best effort to meet the following SLAs for hackers participating in our program:\n\n| Type of Response | SLA in business days |\n| --- | --- |\n| **First Response** | 2 days |\n| **Time to Triage** | 2 days |\n| **Time to Bounty** | 14 days |\n| **Time to Resolution** | Depends on severity and complexity |\n\nWe will make every effort to keep you informed of our progress throughout the remediation process.\n\n# Scope\nOur core target assets are listed in the table below. \n\n\u003e **Note:** For all Web / API targets, API calls initiated from both web and mobile applications are explicitly accepted in scope.\n\n| Asset / Application        | Platform             | Identifier / URL                                                                                       |\n| ------------------------- | ------------------- | ----------------------------------------------------------------------------------------------------- |\n| Trendyol                   | Web / API            | www.trendyol.com                                                                                       |\n| Dolap                      | Web / API            | www.dolap.com                                                                                          |\n| Trendyol Milla             | Web / API            | www.trendyol-milla.com                                                                                 |\n| Trendyol Go Yemek          | Web / API            | www.tgoyemek.com                                                                                       |\n| Trendyol Application       | Android (Play Store) | [trendyol.com](https://play.google.com/store/apps/details?id=trendyol.com)                             |\n| Trendyol Milla Application | Android (Play Store) | [com.trendyol.milla.android](https://play.google.com/store/apps/details?id=com.trendyol.milla.android) |\n| Trendyol Go Application    | Android (Play Store) | [com.trendyol.go](https://play.google.com/store/apps/details?id=com.trendyol.go)                       |\n| Dolap Application          | Android (Play Store) | [com.dolap.android](https://play.google.com/store/apps/details?id=com.dolap.android)                   |\n| Trendyol Milla Application | iOS (App Store)      | [6467634418](https://apps.apple.com/us/app/trendyolmilla/id6467634418)                                 |\n| Trendyol Application       | iOS (App Store)      | [524362642](https://apps.apple.com/tr/app/trendyol-online-al%C4%B1%C5%9Fveri%C5%9F/id524362642)        |\n| Dolap Application          | iOS (App Store)      | [1127881507](https://apps.apple.com/us/app/dolap-i-kinci-el-al%C4%B1%C5%9Fveri%C5%9F/id1127881507)     |\n\n# Test Plan\nWeb traffic to and from DSM properties produces petabytes of data every day. To ensure your testing is identified correctly and our SOC team does not block your research activity, please follow these instructions:\n\n- **Accounts:** Please create accounts using your `username@wearehackerone.com` email address. Some of our properties will require this to be eligible for a bounty.\n- **Custom Header:** You must include the following custom HTTP header in all your traffic:\n  `X-Bug-Bounty: hackerone-{username}`\n\n# Program Rules\nWe expect researchers to adhere to the \"Do No Harm\" principle. In the event of a violation, you may face exclusion from the program:\n\n- **Focus on Impact:** We evaluate reports based on the highest plausible business impact. Show us the worst-case scenario, but do not cross the line into data destruction.\n- **Chaining \u0026 Post-Exploitation:** Chaining vulnerabilities is encouraged to demonstrate impact. However, if you compromise a server or internal system, **stop immediately**. Do not attempt to pivot, port scan internal networks, or escalate privileges further.\n- **Duplicate Transparency:** When duplicates occur, we only award the first fully reproducible report. To maintain transparency, we will strive to add you to the original HackerOne report whenever possible.\n- Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.\n- Submit one vulnerability per report, unless chaining is required.\n- Do not compromise or test DSM accounts that are not your own.\n- Do not threaten DSM, engage in extortion, or demand ransom. \n- Do not perform brute force, DoS attacks, or any actions that degrade DSM services.\n- Social engineering (e.g., phishing, vishing) and physical attacks against DSM facilities are strictly prohibited.\n- Employees, contractors, and their immediate families are prohibited from participating.\n\n# Out-of-Scope Vulnerabilities \u0026 Exclusions\nWhen reporting vulnerabilities, please consider the realistic attack scenario/exploitability, and the technical security impact of the bug. The following issues and testing methods are explicitly excluded from this program:\n\n**1. Excluded Assets \u0026 Features**\n* Any non-DSM applications, third-party integrations, or external hostings.\n* Submitting domain takeovers. We accept notifications of domain takeover for security purposes, but they are not eligible for financial rewards. *Please note that performing the actual takeover of the asset is strictly prohibited.*\n* 0-day vulnerabilities: 0-day and other CVE vulnerabilities may be reported 45 days after initial publication.\n\n**2. Prohibited Testing Methods**\n* **Denial of Service:** Any activity that could lead to the disruption of our service (DoS/DDoS).\n* **Automated Testing:** Running high-frequency automated scans, scanner outputs, and bugs found purely via generic automated tools without manual verification.\n* **Brute Force:** Any form of credential, token, or identifier brute forcing.\n* **Social Engineering:** Any form of social engineering attacks (e.g., phishing, vishing, smishing) targeted at DSM personnel, customer support, or customers.\n* **Physical Attacks:** Conducting any kind of physical attack on DSM’s personnel, office properties, logistics infrastructure, or data centers.\n* **Data Exfiltration:** Exfiltrating production or customer data. Please test only the absolute minimum necessary to validate a proof of concept.\n\n**3. Web Application Exclusions**\n* Clickjacking on pages with no sensitive actions or state-changing functions.\n* Cross-Site Request Forgery (CSRF) on unauthenticated forms, forms with no sensitive actions, or forms with non-impactful business consequences.\n* CORS configurations without a demonstrable, exploitable data-leak scenario.\n* Content spoofing, text injection, or host header injection issues without a significant, proven attack vector (e.g., without being able to modify HTML/CSS dynamically).\n* Open redirects, unless a distinct, secondary security impact can be demonstrated.\n* \"Self\" exploitation vulnerabilities (e.g., Self-XSS, HTML injection affecting only the local session).\n* Flash-based vulnerabilities or legacy Flash-related bugs.\n* Comma Separated Values (CSV) injection without demonstrating a downstream server-side exploit.\n* Form issues regarding missing autocomplete attributes.\n\n**4. Configuration and Defensive Best Practices**\n* Missing security-related HTTP headers (e.g., `X-XSS-Protection`, missing CSP policies) which do not lead directly to a practical vulnerability.\n* Missing `HttpOnly` or `Secure` flags on non-sensitive cookies.\n* Missing email best practices (e.g., invalid, incomplete, or missing SPF/DKIM/DMARC records).\n* Missing best practices in standard SSL/TLS protocol configurations.\n* Software version disclosures, banner grabbing, banner identification issues, descriptive error messages, path disclosures, directory listings, or verbose stack traces without active proof of exploitability.\n* Password complexity guidelines or user enumeration findings.\n\n**5. Environmental \u0026 Client-Side Exclusions**\n* Attacks requiring Man-in-the-Middle (MITM) or prolonged physical access to a user's unlocked device.\n* Vulnerabilities only affecting users of severely outdated or unpatched browsers (defined as being more than 2 stable versions behind the latest released stable browser version).\n* Vulnerabilities relating to root detection, jailbreak status, or certificate pinning on client applications.\n* Vulnerabilities relating to outdated versions of the Android or iOS operating systems.\n* Cloudflare public IP leaks.\n* Previously known vulnerable third-party libraries without a working, contextual Proof of Concept.\n\n# Reporting Requirements\nTo help our triage team validate your findings quickly, all submissions must meet the following baseline requirements. Reports that fail to provide sufficient documentation will be requested to update their report or may be closed as informative.\n\n1. **Clear Summary:** Provide a concise title detailing the vulnerability type and the affected asset/endpoint.\n2. **Detailed Description:** Explain the underlying flaw and how it can be abused.\n3. **Step-by-Step Reproduction Instructions:** Clearly outline the steps required to replicate the vulnerability. Write your steps assuming the reader has no contextual background on your approach.\n4. **Proof of Concept (PoC):** Include explicit PoC material. This can include raw HTTP requests/responses, screenshots, or short screen recordings (MP4 format).\n5. **Impact Evaluation:** Describe the realistic security risk and impact this vulnerability poses to DSM or its customers. Avoid speculative or theoretical harm.\n\n# Disclosure Policy\n* As this is a private program, please do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from DSM.\n* Thank you for joining us in supporting ethical and responsible disclosure. By participating in this program, you agree not to share publicly or privately any details or descriptions of your findings with any third party.\n* Follow HackerOne's standard [disclosure guidelines](https://www.hackerone.com/disclosure-guidelines).\n\n# Confidentiality and Protection of Personal Data\nThe “Confidential Information” shall include, any information provided by DSM to the Hacker (Bug Bounty Program Participants) but not be limited to any information, whether in written, oral, electronic, or other tangible forms including, without limitation, the forms currently available and those made available by new technologies in future, regarding the financial, commercial, technical, professional, market and product-related and all kinds of personal information to be disclosed.\n\nIn principle, DSM does not share personal data with Hacker, and only the Hacker can access personal data based on the legal reason that it is compulsory for the performance of the Articles of Association, limited to the performance of the services provided in the Articles of Association.\n\nIf the Hacker accesses personal data that is not necessary for the performance of the Agreement, it will immediately destroy that information and any copies.\n\nIf you encounter user information that is not your own in the course of your research, please stop and report this activity to our team so we can investigate. Please report to us what information was accessed and delete the data. Do not save, copy, transfer, or otherwise use this data. Continuing to access another person’s data may be regarded as evidence of a lack of good faith.\n\n\n# Safe Harbor\nPlease note that we can only consider your activities to be lawful if they are proportionate and the purpose of your actions is consistent with the purpose of this Policy. We explicitly do not exclude that any attempt to intentionally or grossly negligently attack our systems with the intent to harm us and/or compromise the confidentiality, integrity or availability of our data may be pursued with legal action.\n\n# Legal\nIf reports/notifications falling within the scope of this Policy are conveyed through a different channel, your report/notification will not be taken into consideration by our company. Instead, you will be directed to the BugBounty Program to submit your report. According to our company policies and procedures, reviews of reports and notifications are carried out by our technical teams only when they are transmitted within the scope of the BugBounty program. Therefore, it is necessary to submit your reports through this program.\n\nDSM reserves the right to modify the terms and conditions of this program and your participation in the program constitutes acceptance of all terms. Please check this website regularly as we update our program terms and conditions of participation periodically. We reserve the right to terminate this program at any time.\n\nThank you for keeping DSM and our users safe! \n","has_open_scope":null,"pays_within_one_month":true,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2026-06-19T05:49:08.858Z"},{"id":3775326,"new_policy":"As DSM GRUP DANIŞMANLIK İLETİŞİM VE TİCARET A.Ş. (“DSM”), we highly value security and privacy and  look forward to working with the security community to find security vulnerabilities in order to keep our businesses and customers safe. Off the back of a successful HackerOne Challenge, we are excited to continue leveraging Hacker Powered Security with HackerOne's diverse talent pool.\n\n# Response Targets\nDSM will make its best effort to meet the following SLAs for hackers participating in our program:\n\n| Type of Response | SLA in business days |\n| ------------- | ------------- |\n| First Response | 2 days |\n| Time to Triage | 2 days |\n| Time to Bounty | 14 days |\n| Time to Resolution | depends on severity and complexity |\n\nWe’ll try to keep you informed about our progress throughout the process.\n\n# Disclosure Policy\n* As this is a private program, please do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from DSM\n* Thank you for joining us in supporting ethical and responsible disclosure. By participating in this program, you agree not to share publicly or privately any details or descriptions of your findings with any party.\n* Follow HackerOne's [disclosure guidelines](https://www.hackerone.com/disclosure-guidelines).\n\n#Program Rules\n\nThe program rules for the Bug Bounty program are listed below. In the event of any violation of these rules, we would like to emphasize that performing these actions may result in legal and/or criminal liability for you.\n\n- Social engineering (e.g. phishing, vishing, smishing) is prohibited.\n- Do not perform physical attacks against any DSM facility.\n- Follow HackerOne's disclosure guidelines.\n- Please provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward.\n- Submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact.\n- When duplicates occur, we only award the first report that was received (provided that it can be fully reproduced).\n- Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.\n- Do not compromise or test DSM accounts that are not your own.\n- Do not threaten the DSM and do not try to extort them. Do not act with malicious intent and do not ask for ransom. If you violate this rule, we will exclude you from all current and future programs and none of your reports will be considered. \n- Do not attempt to conduct post-exploitation, including modification or destruction of data, and interruption or degradation of DSM services.\n- Do not perform brute force attacks, denial of service attacks or other attacks that are likely to disrupt, delay or stop DSM's business operations. \n- Reports on outdated versions/builds of in-scope Mobile Apps.\n- It is strictly forbidden for employees, contractors, and members of their immediate families to participate  in the public bounty program or to provide information with an external security researcher to bypass this prohibition. (in which case all parties are ineligible under this program)\n\n\n#Scope\nOur scopes are listed in the assets section below.\n\n- www.trendyol.com (Called from web and mobile apps API will be accepted in scope)\n- m.trendyol.com (Called from web and mobile apps API will be accepted in scope)\n- www.dolap.com (Called from web and mobile apps API will be accepted in scope)\n- www.trendyol-milla.com (Called from web and mobile apps API will be accepted in scope)\n- www.tgoyemek.com (Called from web and mobile apps API will be accepted in scope)\n\n#In-Scope Vulnerability\n| Vulnerability                                               | Severity Range\n|----------                                                  |----------\n|Remote Code Execution                                       |Critical\n|SQL Injection                                               |High - Critical\n|NoSQL Injection                                             |Medium - Critical\n|XXE                                                         |Low - Critical\n|XSS                                                         |Low - Critical\n|Server-Side Request Forgery                                 |Low - Critical\n|Insecure Deserialization                                    |High - Critical\n|Directory Traversal - Local File Inclusion                  |Medium - High\n|Authentication/Authorization Bypass (Broken Access Control) |Medium - High\n|Privilege Escalation                                        |Medium - High\n|Insecure Direct Object Reference                            |Low - Critical\n|Misconfiguration                                            |Low - High\n|Web Cache Deception                                         |Low - High\n|CRLF Injection                                              |Low - Medium\n|Cross Site Request Forgery                                  |Low - Critical\n|Open Redirect                                               |Low\n|Information Disclosure                                      |Low - Critical\n|Request smuggling                                           |Low - High\n|Dependency Confusion                                        |Low - High\n|Mixed Content                                               |Low\n|Server Side Template Injection                              |Low - High\n|Client Side Template Injection                              |Low - Medium\n\n\n#Test Plan\nWeb traffic to and from DSM properties produces petabytes of data every day. When testing, you can make it easier for us to identify your testing traffic against our normal data and the malicious actors out in the world. Please do the following when participating in DSM bug bounty programs:\n\n- Please create accounts using a HackerOne email to help us track security research activity. Where possible, register accounts using your username@wearehackerone.com addresses. Some of our properties will require this to be eligible for a bounty.\n \n- Include a custom HTTP header in all your traffic. Report to us what header you set so we can identify it easily. Our SOC Team is constantly analyzing the traffic so if you don't set this header you might be blocked.\n\n**Format** -\u003e X-Bug-Bounty: hackerone-{username}\n\n**Note:** 0-day and other CVE vulnerabilities may be reported 45 days after initial publication. We have a team dedicated to tracking CVEs as they are released; hosts identified by this team and internally ticketed will not be eligible for bounty.\n\n# Out-of-scope vulnerabilities\n\nWhen reporting vulnerabilities, please consider (1) attack scenario/exploitability, and (2) the security impact of the bug. The following issues are considered out of scope:\n\n- Any non-DSM Applications\n- OTP Rate Limit\n- Issues About Deeplink \n- XSS due to Swagger-UI \n- Clickjacking on pages with no sensitive actions\n- Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive - actions or non-impactful business impact\n- Attacks requiring MITM or physical access to a user's device.\n- Previously known vulnerable libraries without a working Proof of Concept.\n- Comma Separated Values (CSV) injection without demonstrating a vulnerability.\n- Missing best practices in SSL/TLS configuration.\n- Any activity that could lead to the disruption of our service (DoS)\n- Content spoofing and text injection issues without showing a significant attack - vector/without being able to modify HTML/CSS\n- CORS without exploitation\n- Missing security-related HTTP headers which do not lead directly to a vulnerability\n- Rate limiting or brute force issues relying on Cloudflare\n- Missing best practices in Content Security Policy\n- Missing HttpOnly or Secure flags on cookies\n- Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)\n- Vulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]\n- Software version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors)\n- Tabnabbing\n- Open redirect - unless an additional security impact can be demonstrated\n- Host header Injection without a demonstrable impact\n- Issues that require unlikely user interaction\n- Vulnerabilities relating to root detection and cert pinning\n- Vulnerabilities relating to outdated versions of Android\n- Cloudflare public IP leaks\n- Any issues relating to chat features\n- Automated scans and vulnerabilities found by it\n- Performing actions that may negatively affect DSM or its’ customers\n- Conducting any kind of physical attack on DSM’s personnel, property or data centers\n- Exfiltrating data. Please test only the minimum necessary to validate a vulnerability\n- Violating any applicable laws or breaching any applicable agreements in order to discover vulnerabilities\n- Any form of brute force attacks\n- As we have a known issue of missing HTTPOnly flags on session cookies, any vulnerability that leads to Account Take Over under this basis may be capped at a CVSS Medium\n- We'll accept notifications of domain takeover, but they're not eligible for bounty. **Please note that performing the takeover is strictly prohibited.** \n- XML-RPC Vulnerabilities\n- Confidential Information Leakage\n- Missing cookie flags\n- Physical attacks\n- Results of automated scanners\n- Autocomplete attribute on web forms\n- \"Self\" exploitation\n- Flash-based XSS\n- Verbose error pages (without proof of exploitability)\n- Missing Security HTTP Headers (without proof of exploitability)\n- \"Self\" XSS\n- Social Engineering attacks (e.g. phishing, vishing, smishing)\n- Issues related to networking protocols\n- Reports on outdated version/builds of in-scope Mobile Apps\n- Banner Grabbing\n- Scanner Outputs\n- Password Complexity\n- User Enumeration\n- Host header Injection without a demonstrable impact\n- Stack Traces, Path Disclosure, Directory Listings\n- X-XSS-Protection Header\n- Software Version Disclosure\n- Internal pivoting, scanning, exploiting, or exfiltrating data\n- All Flash-related bugs\n\n# Confidentiality and Protection of Personal Data\nThe “Confidential Information” shall include, any information provided by DSM to the Hacker (Bug Bounty Program Participants) but not be limited to any information, whether in written, oral, electronic, or other tangible forms including, without limitation, the forms currently available and those made available by new technologies in future, regarding the financial, commercial, technical, professional, market and product-related and all kinds of personal information to be disclosed.\n\nIn principle, DSM does not share personal data with Hacker, and only the Hacker can access personal data based on the legal reason that it is compulsory for the performance of the Articles of Association, limited to the performance of the services provided in the Articles of Association.\n\nIf the Hacker accesses personal data that is not necessary for the performance of the Agreement, it will immediately destroy that information and any copies.\n\nIf you encounter user information that is not your own in the course of your research, please stop and report this activity to our team so we can investigate. Please report to us what information was accessed and delete the data. Do not save, copy, transfer, or otherwise use this data. Continuing to access another person’s data may be regarded as evidence of a lack of good faith.\n\n\n# Safe Harbor\nPlease note that we can only consider your activities to be lawful if they are proportionate and the purpose of your actions is consistent with the purpose of this Policy. We explicitly do not exclude that any attempt to intentionally or grossly negligently attack our systems with the intent to harm us and/or compromise the confidentiality, integrity or availability of our data may be pursued with legal action.\n\n# Legal\nIf reports/notifications falling within the scope of this Policy are conveyed through a different channel, your report/notification will not be taken into consideration by our company. Instead, you will be directed to the BugBounty Program to submit your report. According to our company policies and procedures, reviews of reports and notifications are carried out by our technical teams only when they are transmitted within the scope of the BugBounty program. Therefore, it is necessary to submit your reports through this program.\n\nDSM reserves the right to modify the terms and conditions of this program and your participation in the program constitutes acceptance of all terms. Please check this website regularly as we update our program terms and conditions of participation periodically. We reserve the right to terminate this program at any time.\n\nThank you for keeping DSM and our users safe! \n","has_open_scope":null,"pays_within_one_month":true,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2026-06-02T06:09:25.094Z"},{"id":3764575,"new_policy":"As DSM GRUP DANIŞMANLIK İLETİŞİM VE TİCARET A.Ş. (“DSM”), we highly value security and privacy and  look forward to working with the security community to find security vulnerabilities in order to keep our businesses and customers safe. Off the back of a successful HackerOne Challenge, we are excited to continue leveraging Hacker Powered Security with HackerOne's diverse talent pool.\n\n# Response Targets\nDSM will make its best effort to meet the following SLAs for hackers participating in our program:\n\n| Type of Response | SLA in business days |\n| ------------- | ------------- |\n| First Response | 2 days |\n| Time to Triage | 2 days |\n| Time to Bounty | 14 days |\n| Time to Resolution | depends on severity and complexity |\n\nWe’ll try to keep you informed about our progress throughout the process.\n\n# Disclosure Policy\n* As this is a private program, please do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from DSM\n* Thank you for joining us in supporting ethical and responsible disclosure. By participating in this program, you agree not to share publicly or privately any details or descriptions of your findings with any party.\n* Follow HackerOne's [disclosure guidelines](https://www.hackerone.com/disclosure-guidelines).\n\n#Program Rules\n\nThe program rules for the Bug Bounty program are listed below. In the event of any violation of these rules, we would like to emphasize that performing these actions may result in legal and/or criminal liability for you.\n\n- Social engineering (e.g. phishing, vishing, smishing) is prohibited.\n- Do not perform physical attacks against any DSM facility.\n- Follow HackerOne's disclosure guidelines.\n- Please provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward.\n- Submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact.\n- When duplicates occur, we only award the first report that was received (provided that it can be fully reproduced).\n- Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.\n- Do not compromise or test DSM accounts that are not your own.\n- Do not threaten the DSM and do not try to extort them. Do not act with malicious intent and do not ask for ransom. If you violate this rule, we will exclude you from all current and future programs and none of your reports will be considered. \n- Do not attempt to conduct post-exploitation, including modification or destruction of data, and interruption or degradation of DSM services.\n- Do not perform brute force attacks, denial of service attacks or other attacks that are likely to disrupt, delay or stop DSM's business operations. \n- Reports on outdated versions/builds of in-scope Mobile Apps.\n- It is strictly forbidden for employees, contractors, and members of their immediate families to participate  in the public bounty program or to provide information with an external security researcher to bypass this prohibition. (in which case all parties are ineligible under this program)\n\n\n#Scope\nOur scopes are listed in the assets section below.\n\n- www.trendyol.com (Called from web and mobile apps API will be accepted in scope)\n- m.trendyol.com (Called from web and mobile apps API will be accepted in scope)\n- www.dolap.com (Called from web and mobile apps API will be accepted in scope)\n- www.trendyol-milla.com (Called from web and mobile apps API will be accepted in scope)\n- www.tgoyemek.com (Called from web and mobile apps API will be accepted in scope)\n\n#In-Scope Vulnerability\n| Vulnerability                                               | Severity Range\n|----------                                                  |----------\n|Remote Code Execution                                       |Critical\n|SQL Injection                                               |High - Critical\n|NoSQL Injection                                             |Medium - Critical\n|XXE                                                         |Low - Critical\n|XSS                                                         |Low - Critical\n|Server-Side Request Forgery                                 |Low - Critical\n|Insecure Deserialization                                    |High - Critical\n|Directory Traversal - Local File Inclusion                  |Medium - High\n|Authentication/Authorization Bypass (Broken Access Control) |Medium - High\n|Privilege Escalation                                        |Medium - High\n|Insecure Direct Object Reference                            |Low - Critical\n|Misconfiguration                                            |Low - High\n|Web Cache Deception                                         |Low - High\n|CRLF Injection                                              |Low - Medium\n|Cross Site Request Forgery                                  |Low - Critical\n|Open Redirect                                               |Low\n|Information Disclosure                                      |Low - Critical\n|Request smuggling                                           |Low - High\n|Dependency Confusion                                        |Low - High\n|Mixed Content                                               |Low\n|Server Side Template Injection                              |Low - High\n|Client Side Template Injection                              |Low - Medium\n\n\n#Test Plan\nWeb traffic to and from DSM properties produces petabytes of data every day. When testing, you can make it easier for us to identify your testing traffic against our normal data and the malicious actors out in the world. Please do the following when participating in DSM bug bounty programs:\n\n- Please create accounts using a HackerOne email to help us track security research activity. Where possible, register accounts using your username@wearehackerone.com addresses. Some of our properties will require this to be eligible for a bounty.\n \n- Include a custom HTTP header in all your traffic. Report to us what header you set so we can identify it easily. Our SOC Team is constantly analyzing the traffic so if you don't set this header you might be blocked.\n\n**Format** -\u003e X-Bug-Bounty: hackerone-{username}\n\n**Note:** 0-day and other CVE vulnerabilities may be reported 45 days after initial publication. We have a team dedicated to tracking CVEs as they are released; hosts identified by this team and internally ticketed will not be eligible for bounty.\n\n# Out-of-scope vulnerabilities\n\nWhen reporting vulnerabilities, please consider (1) attack scenario/exploitability, and (2) the security impact of the bug. The following issues are considered out of scope:\n\n- Any non-DSM Applications\n- OTP Rate Limit\n- Issues About Deeplink \n- XSS due to Swagger-UI \n- Clickjacking on pages with no sensitive actions\n- Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive - actions or non-impactful business impact\n- Attacks requiring MITM or physical access to a user's device.\n- Previously known vulnerable libraries without a working Proof of Concept.\n- Comma Separated Values (CSV) injection without demonstrating a vulnerability.\n- Missing best practices in SSL/TLS configuration.\n- Any activity that could lead to the disruption of our service (DoS)\n- Content spoofing and text injection issues without showing a significant attack - vector/without being able to modify HTML/CSS\n- CORS without exploitation\n- Missing security-related HTTP headers which do not lead directly to a vulnerability\n- Rate limiting or brute force issues relying on Cloudflare\n- Missing best practices in Content Security Policy\n- Missing HttpOnly or Secure flags on cookies\n- Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)\n- Vulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]\n- Software version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors)\n- Tabnabbing\n- Open redirect - unless an additional security impact can be demonstrated\n- Host header Injection without a demonstrable impact\n- Issues that require unlikely user interaction\n- Vulnerabilities relating to root detection and cert pinning\n- Vulnerabilities relating to outdated versions of Android\n- Cloudflare public IP leaks\n- Any issues relating to chat features\n- Automated scans and vulnerabilities found by it\n- Performing actions that may negatively affect DSM or its’ customers\n- Conducting any kind of physical attack on DSM’s personnel, property or data centers\n- Exfiltrating data. Please test only the minimum necessary to validate a vulnerability\n- Violating any applicable laws or breaching any applicable agreements in order to discover vulnerabilities\n- Any form of brute force attacks\n- As we have a known issue of missing HTTPOnly flags on session cookies, any vulnerability that leads to Account Take Over under this basis may be capped at a CVSS Medium\n- We'll accept notifications of domain takeover, but they're not eligible for bounty. **Please note that performing the takeover is strictly prohibited.** \n- XML-RPC Vulnerabilities\n- Confidential Information Leakage\n- Missing cookie flags\n- Physical attacks\n- Results of automated scanners\n- Autocomplete attribute on web forms\n- \"Self\" exploitation\n- Flash-based XSS\n- Verbose error pages (without proof of exploitability)\n- Missing Security HTTP Headers (without proof of exploitability)\n- \"Self\" XSS\n- Social Engineering attacks\n- Issues related to networking protocols\n- Reports on outdated version/builds of in-scope Mobile Apps\n- Banner Grabbing\n- Scanner Outputs\n- Password Complexity\n- User Enumeration\n- Host header Injection without a demonstrable impact\n- Stack Traces, Path Disclosure, Directory Listings\n- X-XSS-Protection Header\n- Software Version Disclosure\n- Internal pivoting, scanning, exploiting, or exfiltrating data\n- All Flash-related bugs\n\n# Confidentiality and Protection of Personal Data\nThe “Confidential Information” shall include, any information provided by DSM to the Hacker (Bug Bounty Program Participants) but not be limited to any information, whether in written, oral, electronic, or other tangible forms including, without limitation, the forms currently available and those made available by new technologies in future, regarding the financial, commercial, technical, professional, market and product-related and all kinds of personal information to be disclosed.\n\nIn principle, DSM does not share personal data with Hacker, and only the Hacker can access personal data based on the legal reason that it is compulsory for the performance of the Articles of Association, limited to the performance of the services provided in the Articles of Association.\n\nIf the Hacker accesses personal data that is not necessary for the performance of the Agreement, it will immediately destroy that information and any copies.\n\nIf you encounter user information that is not your own in the course of your research, please stop and report this activity to our team so we can investigate. Please report to us what information was accessed and delete the data. Do not save, copy, transfer, or otherwise use this data. Continuing to access another person’s data may be regarded as evidence of a lack of good faith.\n\n\n# Safe Harbor\nPlease note that we can only consider your activities to be lawful if they are proportionate and the purpose of your actions is consistent with the purpose of this Policy. We explicitly do not exclude that any attempt to intentionally or grossly negligently attack our systems with the intent to harm us and/or compromise the confidentiality, integrity or availability of our data may be pursued with legal action.\n\n# Legal\nIf reports/notifications falling within the scope of this Policy are conveyed through a different channel, your report/notification will not be taken into consideration by our company. Instead, you will be directed to the BugBounty Program to submit your report. According to our company policies and procedures, reviews of reports and notifications are carried out by our technical teams only when they are transmitted within the scope of the BugBounty program. Therefore, it is necessary to submit your reports through this program.\n\nDSM reserves the right to modify the terms and conditions of this program and your participation in the program constitutes acceptance of all terms. Please check this website regularly as we update our program terms and conditions of participation periodically. We reserve the right to terminate this program at any time.\n\nThank you for keeping DSM and our users safe! \n","has_open_scope":null,"pays_within_one_month":true,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2025-10-14T12:22:50.687Z"},{"id":3762156,"new_policy":"As DSM GRUP DANIŞMANLIK İLETİŞİM VE TİCARET A.Ş. (“DSM”), we highly value security and privacy and  look forward to working with the security community to find security vulnerabilities in order to keep our businesses and customers safe. Off the back of a successful HackerOne Challenge, we are excited to continue leveraging Hacker Powered Security with HackerOne's diverse talent pool.\n\n# Response Targets\nDSM will make its best effort to meet the following SLAs for hackers participating in our program:\n\n| Type of Response | SLA in business days |\n| ------------- | ------------- |\n| First Response | 2 days |\n| Time to Triage | 2 days |\n| Time to Bounty | 14 days |\n| Time to Resolution | depends on severity and complexity |\n\nWe’ll try to keep you informed about our progress throughout the process.\n\n# Disclosure Policy\n* As this is a private program, please do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from DSM\n* Thank you for joining us in supporting ethical and responsible disclosure. By participating in this program, you agree not to share publicly or privately any details or descriptions of your findings with any party.\n* Follow HackerOne's [disclosure guidelines](https://www.hackerone.com/disclosure-guidelines).\n\n#Program Rules\n\nThe program rules for the Bug Bounty program are listed below. In the event of any violation of these rules, we would like to emphasize that performing these actions may result in legal and/or criminal liability for you.\n\n- Social engineering (e.g. phishing, vishing, smishing) is prohibited.\n- Do not perform physical attacks against any DSM facility.\n- Follow HackerOne's disclosure guidelines.\n- Please provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward.\n- Submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact.\n- When duplicates occur, we only award the first report that was received (provided that it can be fully reproduced).\n- Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.\n- Do not compromise or test DSM accounts that are not your own.\n- Do not threaten the DSM and do not try to extort them. Do not act with malicious intent and do not ask for ransom. If you violate this rule, we will exclude you from all current and future programs and none of your reports will be considered. \n- Do not attempt to conduct post-exploitation, including modification or destruction of data, and interruption or degradation of DSM services.\n- Do not perform brute force attacks, denial of service attacks or other attacks that are likely to disrupt, delay or stop DSM's business operations. \n- Reports on outdated versions/builds of in-scope Mobile Apps.\n- It is strictly forbidden for employees, contractors, and members of their immediate families to participate  in the public bounty program or to provide information with an external security researcher to bypass this prohibition. (in which case all parties are ineligible under this program)\n\n\n#Scope\nOur scopes are listed in the assets section below.\n\n- www.trendyol.com (Called from web and mobile apps API will be accepted in scope)\n- m.trendyol.com (Called from web and mobile apps API will be accepted in scope)\n- www.dolap.com (Called from web and mobile apps API will be accepted in scope)\n- www.trendyol-milla.com (Called from web and mobile apps API will be accepted in scope)\n- www.tgoyemek.com (Called from web and mobile apps API will be accepted in scope)\n\n#In-Scope Vulnerability\n| Vulnerability                                               | Severity Range\n|----------                                                  |----------\n|Remote Code Execution                                       |Critical\n|SQL Injection                                               |High - Critical\n|NoSQL Injection                                             |Medium - Critical\n|XXE                                                         |Low - Critical\n|XSS                                                         |Low - Critical\n|Server-Side Request Forgery                                 |Low - Critical\n|Insecure Deserialization                                    |High - Critical\n|Directory Traversal - Local File Inclusion                  |Medium - High\n|Authentication/Authorization Bypass (Broken Access Control) |Medium - High\n|Privilege Escalation                                        |Medium - High\n|Insecure Direct Object Reference                            |Low - Critical\n|Misconfiguration                                            |Low - High\n|Web Cache Deception                                         |Low - High\n|CRLF Injection                                              |Low - Medium\n|Cross Site Request Forgery                                  |Low - Critical\n|Open Redirect                                               |Low\n|Information Disclosure                                      |Low - Critical\n|Request smuggling                                           |Low - High\n|Dependency Confusion                                        |Low - High\n|Mixed Content                                               |Low\n|Server Side Template Injection                              |Low - High\n|Client Side Template Injection                              |Low - Medium\n|Subdomain Takeover                                          |Low - High\n\n#Test Plan\nWeb traffic to and from DSM properties produces petabytes of data every day. When testing, you can make it easier for us to identify your testing traffic against our normal data and the malicious actors out in the world. Please do the following when participating in DSM bug bounty programs:\n\n- Please create accounts using a HackerOne email to help us track security research activity. Where possible, register accounts using your username@wearehackerone.com addresses. Some of our properties will require this to be eligible for a bounty.\n \n- Include a custom HTTP header in all your traffic. Report to us what header you set so we can identify it easily. Our SOC Team is constantly analyzing the traffic so if you don't set this header you might be blocked.\n\n**Format** -\u003e X-Bug-Bounty: hackerone-{username}\n\n**Note:** 0-day and other CVE vulnerabilities may be reported 45 days after initial publication. We have a team dedicated to tracking CVEs as they are released; hosts identified by this team and internally ticketed will not be eligible for bounty.\n\n# Out-of-scope vulnerabilities\n\nWhen reporting vulnerabilities, please consider (1) attack scenario/exploitability, and (2) the security impact of the bug. The following issues are considered out of scope:\n\n- Any non-DSM Applications\n- OTP Rate Limit\n- Issues About Deeplink \n- XSS due to Swagger-UI \n- Clickjacking on pages with no sensitive actions\n- Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive - actions or non-impactful business impact\n- Attacks requiring MITM or physical access to a user's device.\n- Previously known vulnerable libraries without a working Proof of Concept.\n- Comma Separated Values (CSV) injection without demonstrating a vulnerability.\n- Missing best practices in SSL/TLS configuration.\n- Any activity that could lead to the disruption of our service (DoS)\n- Content spoofing and text injection issues without showing a significant attack - vector/without being able to modify HTML/CSS\n- CORS without exploitation\n- Missing security-related HTTP headers which do not lead directly to a vulnerability\n- Rate limiting or brute force issues relying on Cloudflare\n- Missing best practices in Content Security Policy\n- Missing HttpOnly or Secure flags on cookies\n- Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)\n- Vulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]\n- Software version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors)\n- Tabnabbing\n- Open redirect - unless an additional security impact can be demonstrated\n- Host header Injection without a demonstrable impact\n- Issues that require unlikely user interaction\n- Vulnerabilities relating to root detection and cert pinning\n- Vulnerabilities relating to outdated versions of Android\n- Cloudflare public IP leaks\n- Any issues relating to chat features\n- Automated scans and vulnerabilities found by it\n- Performing actions that may negatively affect DSM or its’ customers\n- Conducting any kind of physical attack on DSM’s personnel, property or data centers\n- Exfiltrating data. Please test only the minimum necessary to validate a vulnerability\n- Violating any applicable laws or breaching any applicable agreements in order to discover vulnerabilities\n- Any form of brute force attacks\n- As we have a known issue of missing HTTPOnly flags on session cookies, any vulnerability that leads to Account Take Over under this basis may be capped at a CVSS Medium\n- We'll accept notifications of domain takeover, but they're not eligible for bounty. **Please note that performing the takeover is strictly prohibited.** \n- XML-RPC Vulnerabilities\n- Confidential Information Leakage\n- Missing cookie flags\n- Physical attacks\n- Results of automated scanners\n- Autocomplete attribute on web forms\n- \"Self\" exploitation\n- Flash-based XSS\n- Verbose error pages (without proof of exploitability)\n- Missing Security HTTP Headers (without proof of exploitability)\n- \"Self\" XSS\n- Social Engineering attacks\n- Issues related to networking protocols\n- Reports on outdated version/builds of in-scope Mobile Apps\n- Banner Grabbing\n- Scanner Outputs\n- Password Complexity\n- User Enumeration\n- Host header Injection without a demonstrable impact\n- Stack Traces, Path Disclosure, Directory Listings\n- X-XSS-Protection Header\n- Software Version Disclosure\n- Internal pivoting, scanning, exploiting, or exfiltrating data\n- All Flash-related bugs\n\n# Confidentiality and Protection of Personal Data\nThe “Confidential Information” shall include, any information provided by DSM to the Hacker (Bug Bounty Program Participants) but not be limited to any information, whether in written, oral, electronic, or other tangible forms including, without limitation, the forms currently available and those made available by new technologies in future, regarding the financial, commercial, technical, professional, market and product-related and all kinds of personal information to be disclosed.\n\nIn principle, DSM does not share personal data with Hacker, and only the Hacker can access personal data based on the legal reason that it is compulsory for the performance of the Articles of Association, limited to the performance of the services provided in the Articles of Association.\n\nIf the Hacker accesses personal data that is not necessary for the performance of the Agreement, it will immediately destroy that information and any copies.\n\nIf you encounter user information that is not your own in the course of your research, please stop and report this activity to our team so we can investigate. Please report to us what information was accessed and delete the data. Do not save, copy, transfer, or otherwise use this data. Continuing to access another person’s data may be regarded as evidence of a lack of good faith.\n\n\n# Safe Harbor\nPlease note that we can only consider your activities to be lawful if they are proportionate and the purpose of your actions is consistent with the purpose of this Policy. We explicitly do not exclude that any attempt to intentionally or grossly negligently attack our systems with the intent to harm us and/or compromise the confidentiality, integrity or availability of our data may be pursued with legal action.\n\n# Legal\nIf reports/notifications falling within the scope of this Policy are conveyed through a different channel, your report/notification will not be taken into consideration by our company. Instead, you will be directed to the BugBounty Program to submit your report. According to our company policies and procedures, reviews of reports and notifications are carried out by our technical teams only when they are transmitted within the scope of the BugBounty program. Therefore, it is necessary to submit your reports through this program.\n\nDSM reserves the right to modify the terms and conditions of this program and your participation in the program constitutes acceptance of all terms. Please check this website regularly as we update our program terms and conditions of participation periodically. We reserve the right to terminate this program at any time.\n\nThank you for keeping DSM and our users safe! \n","has_open_scope":null,"pays_within_one_month":true,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2025-09-01T10:54:39.204Z"},{"id":3762023,"new_policy":"As DSM GRUP DANIŞMANLIK İLETİŞİM VE TİCARET A.Ş. (“DSM”), we highly value security and privacy and  look forward to working with the security community to find security vulnerabilities in order to keep our businesses and customers safe. Off the back of a successful HackerOne Challenge, we are excited to continue leveraging Hacker Powered Security with HackerOne's diverse talent pool.\n\n# Response Targets\nDSM will make its best effort to meet the following SLAs for hackers participating in our program:\n\n| Type of Response | SLA in business days |\n| ------------- | ------------- |\n| First Response | 2 days |\n| Time to Triage | 2 days |\n| Time to Bounty | 14 days |\n| Time to Resolution | depends on severity and complexity |\n\nWe’ll try to keep you informed about our progress throughout the process.\n\n# Disclosure Policy\n* As this is a private program, please do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from DSM\n* Thank you for joining us in supporting ethical and responsible disclosure. By participating in this program, you agree not to share publicly or privately any details or descriptions of your findings with any party.\n* Follow HackerOne's [disclosure guidelines](https://www.hackerone.com/disclosure-guidelines).\n\n#Program Rules\n\nThe program rules for the Bug Bounty program are listed below. In the event of any violation of these rules, we would like to emphasize that performing these actions may result in legal and/or criminal liability for you.\n\n- Social engineering (e.g. phishing, vishing, smishing) is prohibited.\n- Do not perform physical attacks against any DSM facility.\n- Follow HackerOne's disclosure guidelines.\n- Please provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward.\n- Submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact.\n- When duplicates occur, we only award the first report that was received (provided that it can be fully reproduced).\n- Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.\n- Do not compromise or test DSM accounts that are not your own.\n- Do not threaten the DSM and do not try to extort them. Do not act with malicious intent and do not ask for ransom. If you violate this rule, we will exclude you from all current and future programs and none of your reports will be considered. \n- Do not attempt to conduct post-exploitation, including modification or destruction of data, and interruption or degradation of DSM services.\n- Do not perform brute force attacks, denial of service attacks or other attacks that are likely to disrupt, delay or stop DSM's business operations. \n- Reports on outdated versions/builds of in-scope Mobile Apps.\n- It is strictly forbidden for employees, contractors, and members of their immediate families to participate  in the public bounty program or to provide information with an external security researcher to bypass this prohibition. (in which case all parties are ineligible under this program)\n\n\n#Scope\nOur scopes are listed in the assets section below.\n\n- www.trendyol.com (Called from web and mobile apps API will be accepted in scope)\n- m.trendyol.com (Called from web and mobile apps API will be accepted in scope)\n- www.dolap.com (Called from web and mobile apps API will be accepted in scope)\n- www.trendyol-milla.com (Called from web and mobile apps API will be accepted in scope)\n\n#In-Scope Vulnerability\n| Vulnerability                                               | Severity Range\n|----------                                                  |----------\n|Remote Code Execution                                       |Critical\n|SQL Injection                                               |High - Critical\n|NoSQL Injection                                             |Medium - Critical\n|XXE                                                         |Low - Critical\n|XSS                                                         |Low - Critical\n|Server-Side Request Forgery                                 |Low - Critical\n|Insecure Deserialization                                    |High - Critical\n|Directory Traversal - Local File Inclusion                  |Medium - High\n|Authentication/Authorization Bypass (Broken Access Control) |Medium - High\n|Privilege Escalation                                        |Medium - High\n|Insecure Direct Object Reference                            |Low - Critical\n|Misconfiguration                                            |Low - High\n|Web Cache Deception                                         |Low - High\n|CRLF Injection                                              |Low - Medium\n|Cross Site Request Forgery                                  |Low - Critical\n|Open Redirect                                               |Low\n|Information Disclosure                                      |Low - Critical\n|Request smuggling                                           |Low - High\n|Dependency Confusion                                        |Low - High\n|Mixed Content                                               |Low\n|Server Side Template Injection                              |Low - High\n|Client Side Template Injection                              |Low - Medium\n|Subdomain Takeover                                          |Low - High\n\n#Test Plan\nWeb traffic to and from DSM properties produces petabytes of data every day. When testing, you can make it easier for us to identify your testing traffic against our normal data and the malicious actors out in the world. Please do the following when participating in DSM bug bounty programs:\n\n- Please create accounts using a HackerOne email to help us track security research activity. Where possible, register accounts using your username@wearehackerone.com addresses. Some of our properties will require this to be eligible for a bounty.\n \n- Include a custom HTTP header in all your traffic. Report to us what header you set so we can identify it easily. Our SOC Team is constantly analyzing the traffic so if you don't set this header you might be blocked.\n\n**Format** -\u003e X-Bug-Bounty: hackerone-{username}\n\n**Note:** 0-day and other CVE vulnerabilities may be reported 45 days after initial publication. We have a team dedicated to tracking CVEs as they are released; hosts identified by this team and internally ticketed will not be eligible for bounty.\n\n# Out-of-scope vulnerabilities\n\nWhen reporting vulnerabilities, please consider (1) attack scenario/exploitability, and (2) the security impact of the bug. The following issues are considered out of scope:\n\n- Any non-DSM Applications\n- OTP Rate Limit\n- Issues About Deeplink \n- XSS due to Swagger-UI \n- Clickjacking on pages with no sensitive actions\n- Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive - actions or non-impactful business impact\n- Attacks requiring MITM or physical access to a user's device.\n- Previously known vulnerable libraries without a working Proof of Concept.\n- Comma Separated Values (CSV) injection without demonstrating a vulnerability.\n- Missing best practices in SSL/TLS configuration.\n- Any activity that could lead to the disruption of our service (DoS)\n- Content spoofing and text injection issues without showing a significant attack - vector/without being able to modify HTML/CSS\n- CORS without exploitation\n- Missing security-related HTTP headers which do not lead directly to a vulnerability\n- Rate limiting or brute force issues relying on Cloudflare\n- Missing best practices in Content Security Policy\n- Missing HttpOnly or Secure flags on cookies\n- Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)\n- Vulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]\n- Software version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors)\n- Tabnabbing\n- Open redirect - unless an additional security impact can be demonstrated\n- Host header Injection without a demonstrable impact\n- Issues that require unlikely user interaction\n- Vulnerabilities relating to root detection and cert pinning\n- Vulnerabilities relating to outdated versions of Android\n- Cloudflare public IP leaks\n- Any issues relating to chat features\n- Automated scans and vulnerabilities found by it\n- Performing actions that may negatively affect DSM or its’ customers\n- Conducting any kind of physical attack on DSM’s personnel, property or data centers\n- Exfiltrating data. Please test only the minimum necessary to validate a vulnerability\n- Violating any applicable laws or breaching any applicable agreements in order to discover vulnerabilities\n- Any form of brute force attacks\n- As we have a known issue of missing HTTPOnly flags on session cookies, any vulnerability that leads to Account Take Over under this basis may be capped at a CVSS Medium\n- We'll accept notifications of domain takeover, but they're not eligible for bounty. **Please note that performing the takeover is strictly prohibited.** \n- XML-RPC Vulnerabilities\n- Confidential Information Leakage\n- Missing cookie flags\n- Physical attacks\n- Results of automated scanners\n- Autocomplete attribute on web forms\n- \"Self\" exploitation\n- Flash-based XSS\n- Verbose error pages (without proof of exploitability)\n- Missing Security HTTP Headers (without proof of exploitability)\n- \"Self\" XSS\n- Social Engineering attacks\n- Issues related to networking protocols\n- Reports on outdated version/builds of in-scope Mobile Apps\n- Banner Grabbing\n- Scanner Outputs\n- Password Complexity\n- User Enumeration\n- Host header Injection without a demonstrable impact\n- Stack Traces, Path Disclosure, Directory Listings\n- X-XSS-Protection Header\n- Software Version Disclosure\n- Internal pivoting, scanning, exploiting, or exfiltrating data\n- All Flash-related bugs\n\n# Confidentiality and Protection of Personal Data\nThe “Confidential Information” shall include, any information provided by DSM to the Hacker (Bug Bounty Program Participants) but not be limited to any information, whether in written, oral, electronic, or other tangible forms including, without limitation, the forms currently available and those made available by new technologies in future, regarding the financial, commercial, technical, professional, market and product-related and all kinds of personal information to be disclosed.\n\nIn principle, DSM does not share personal data with Hacker, and only the Hacker can access personal data based on the legal reason that it is compulsory for the performance of the Articles of Association, limited to the performance of the services provided in the Articles of Association.\n\nIf the Hacker accesses personal data that is not necessary for the performance of the Agreement, it will immediately destroy that information and any copies.\n\nIf you encounter user information that is not your own in the course of your research, please stop and report this activity to our team so we can investigate. Please report to us what information was accessed and delete the data. Do not save, copy, transfer, or otherwise use this data. Continuing to access another person’s data may be regarded as evidence of a lack of good faith.\n\n\n# Safe Harbor\nPlease note that we can only consider your activities to be lawful if they are proportionate and the purpose of your actions is consistent with the purpose of this Policy. We explicitly do not exclude that any attempt to intentionally or grossly negligently attack our systems with the intent to harm us and/or compromise the confidentiality, integrity or availability of our data may be pursued with legal action.\n\n# Legal\nIf reports/notifications falling within the scope of this Policy are conveyed through a different channel, your report/notification will not be taken into consideration by our company. Instead, you will be directed to the BugBounty Program to submit your report. According to our company policies and procedures, reviews of reports and notifications are carried out by our technical teams only when they are transmitted within the scope of the BugBounty program. Therefore, it is necessary to submit your reports through this program.\n\nDSM reserves the right to modify the terms and conditions of this program and your participation in the program constitutes acceptance of all terms. Please check this website regularly as we update our program terms and conditions of participation periodically. We reserve the right to terminate this program at any time.\n\nThank you for keeping DSM and our users safe! \n","has_open_scope":null,"pays_within_one_month":true,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2025-08-28T14:29:18.593Z"},{"id":3713615,"new_policy":"As DSM GRUP DANIŞMANLIK İLETİŞİM VE TİCARET A.Ş. (“DSM”), we highly value security and privacy and  look forward to working with the security community to find security vulnerabilities in order to keep our businesses and customers safe. Off the back of a successful HackerOne Challenge, we are excited to continue leveraging Hacker Powered Security with HackerOne's diverse talent pool.\n\n# Response Targets\nDSM will make its best effort to meet the following SLAs for hackers participating in our program:\n\n| Type of Response | SLA in business days |\n| ------------- | ------------- |\n| First Response | 2 days |\n| Time to Triage | 2 days |\n| Time to Bounty | 14 days |\n| Time to Resolution | depends on severity and complexity |\n\nWe’ll try to keep you informed about our progress throughout the process.\n\n# Disclosure Policy\n* As this is a private program, please do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from DSM\n* Thank you for joining us in supporting ethical and responsible disclosure. By participating in this program, you agree not to share publicly or privately any details or descriptions of your findings with any party.\n* Follow HackerOne's [disclosure guidelines](https://www.hackerone.com/disclosure-guidelines).\n\n#Program Rules\n\nThe program rules for the Bug Bounty program are listed below. In the event of any violation of these rules, we would like to emphasize that performing these actions may result in legal and/or criminal liability for you.\n\n- Social engineering (e.g. phishing, vishing, smishing) is prohibited.\n- Do not perform physical attacks against any DSM facility.\n- Follow HackerOne's disclosure guidelines.\n- Please provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward.\n- Submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact.\n- When duplicates occur, we only award the first report that was received (provided that it can be fully reproduced).\n- Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.\n- Do not compromise or test DSM accounts that are not your own.\n- Do not threaten the DSM and do not try to extort them. Do not act with malicious intent and do not ask for ransom. If you violate this rule, we will exclude you from all current and future programs and none of your reports will be considered. \n- Do not attempt to conduct post-exploitation, including modification or destruction of data, and interruption or degradation of DSM services.\n- Do not perform brute force attacks, denial of service attacks or other attacks that are likely to disrupt, delay or stop DSM's business operations. \n- Reports on outdated versions/builds of in-scope Mobile Apps.\n- It is strictly forbidden for employees, contractors, and members of their immediate families to participate  in the public bounty program or to provide information with an external security researcher to bypass this prohibition. (in which case all parties are ineligible under this program)\n\n\n#Scope\nOur scopes are listed in the assets section below.\n\n- www.trendyol.com (Called from web and mobile apps API will be accepted in scope)\n- m.trendyol.com (Called from web and mobile apps API will be accepted in scope)\n- www.dolap.com (Called from web and mobile apps API will be accepted in scope)\n- www.trendyol-milla.com (Called from web and mobile apps API will be accepted in scope)\n\n#In-Scope Vulnerability\n| Vulnerability                                               | Severity Range\n|----------                                                  |----------\n|Remote Code Execution                                       |Critical\n|SQL Injection                                               |High - Critical\n|NoSQL Injection                                             |Medium - Critical\n|XXE                                                         |Low - Critical\n|XSS                                                         |Low - Critical\n|Server-Side Request Forgery                                 |Low - Critical\n|Insecure Deserialization                                    |High - Critical\n|Directory Traversal - Local File Inclusion                  |Medium - High\n|Authentication/Authorization Bypass (Broken Access Control) |Medium - High\n|Privilege Escalation                                        |Medium - High\n|Insecure Direct Object Reference                            |Low - Critical\n|Misconfiguration                                            |Low - High\n|Web Cache Deception                                         |Low - High\n|CRLF Injection                                              |Low - Medium\n|Cross Site Request Forgery                                  |Low - Critical\n|Open Redirect                                               |Low\n|Information Disclosure                                      |Low - Critical\n|Request smuggling                                           |Low - High\n|Dependency Confusion                                        |Low - High\n|Mixed Content                                               |Low\n|Server Side Template Injection                              |Low - High\n|Client Side Template Injection                              |Low - Medium\n|Subdomain Takeover                                          |Low - High\n\n#Test Plan\nWeb traffic to and from DSM properties produces petabytes of data every day. When testing, you can make it easier for us to identify your testing traffic against our normal data and the malicious actors out in the world. Please do the following when participating in DSM bug bounty programs:\n\n- Please create accounts using a HackerOne email to help us track security research activity. Where possible, register accounts using your username@wearehackerone.com addresses. Some of our properties will require this to be eligible for a bounty.\n \n- Include a custom HTTP header in all your traffic. Report to us what header you set so we can identify it easily. Our SOC Team is constantly analyzing the traffic so if you don't set this header you might be blocked.\n\n**Format** -\u003e X-Bug-Bounty: hackerone-{username}\n\n**Note:** 0-day and other CVE vulnerabilities may be reported 45 days after initial publication. We have a team dedicated to tracking CVEs as they are released; hosts identified by this team and internally ticketed will not be eligible for bounty.\n\n# Out-of-scope vulnerabilities\n\nWhen reporting vulnerabilities, please consider (1) attack scenario/exploitability, and (2) the security impact of the bug. The following issues are considered out of scope:\n\n- Any non-DSM Applications\n- OTP Rate Limit\n- Issues About Deeplink \n- XSS due to Swagger-UI \n- Clickjacking on pages with no sensitive actions\n- Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive - actions or non-impactful business impact\n- Attacks requiring MITM or physical access to a user's device.\n- Previously known vulnerable libraries without a working Proof of Concept.\n- Comma Separated Values (CSV) injection without demonstrating a vulnerability.\n- Missing best practices in SSL/TLS configuration.\n- Any activity that could lead to the disruption of our service (DoS)\n- Content spoofing and text injection issues without showing a significant attack - vector/without being able to modify HTML/CSS\n- CORS without exploitation\n- Missing security-related HTTP headers which do not lead directly to a vulnerability\n- Rate limiting or brute force issues relying on Cloudflare\n- Missing best practices in Content Security Policy\n- Missing HttpOnly or Secure flags on cookies\n- Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)\n- Vulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]\n- Software version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors)\n- Tabnabbing\n- Open redirect - unless an additional security impact can be demonstrated\n- Host header Injection without a demonstrable impact\n- Issues that require unlikely user interaction\n- Vulnerabilities relating to root detection and cert pinning\n- Vulnerabilities relating to outdated versions of Android\n- Cloudflare public IP leaks\n- Any issues relating to chat features\n- Automated scans and vulnerabilities found by it\n- Performing actions that may negatively affect DSM or its’ customers\n- Conducting any kind of physical attack on DSM’s personnel, property or data centers\n- Exfiltrating data. Please test only the minimum necessary to validate a vulnerability\n- Violating any applicable laws or breaching any applicable agreements in order to discover vulnerabilities\n- Any form of brute force attacks\n- As we have a known issue of missing HTTPOnly flags on session cookies, any vulnerability that leads to Account Take Over under this basis may be capped at a CVSS Medium\n- We'll accept notifications of domain takeover, but they're not eligible for bounty. **Please note that performing the takeover is strictly prohibited.** \n- XML-RPC Vulnerabilities\n- Confidential Information Leakage\n- Missing cookie flags\n- Physical attacks\n- Results of automated scanners\n- Autocomplete attribute on web forms\n- \"Self\" exploitation\n- Flash-based XSS\n- Verbose error pages (without proof of exploitability)\n- Missing Security HTTP Headers (without proof of exploitability)\n- \"Self\" XSS\n- Social Engineering attacks\n- Issues related to networking protocols\n- Reports on outdated version/builds of in-scope Mobile Apps\n- Banner Grabbing\n- Scanner Outputs\n- Password Complexity\n- User Enumeration\n- Host header Injection without a demonstrable impact\n- Stack Traces, Path Disclosure, Directory Listings\n- X-XSS-Protection Header\n- Software Version Disclosure\n- Internal pivoting, scanning, exploiting, or exfiltrating data\n- All Flash-related bugs\n\n# Confidentiality and Protection of Personal Data\nThe “Confidential Information” shall include, any information provided by DSM to the Hacker (Bug Bounty Program Participants) but not be limited to any information, whether in written, oral, electronic, or other tangible forms including, without limitation, the forms currently available and those made available by new technologies in future, regarding the financial, commercial, technical, professional, market and product-related and all kinds of personal information to be disclosed.\n\nIn principle, DSM does not share personal data with Hacker, and only the Hacker can access personal data based on the legal reason that it is compulsory for the performance of the Articles of Association, limited to the performance of the services provided in the Articles of Association.\n\nIf the Hacker accesses personal data that is not necessary for the performance of the Agreement, it will immediately destroy that information and any copies.\n\nIf you encounter user information that is not your own in the course of your research, please stop and report this activity to our team so we can investigate. Please report to us what information was accessed and delete the data. Do not save, copy, transfer, or otherwise use this data. Continuing to access another person’s data may be regarded as evidence of a lack of good faith.\n\n\n# Safe Harbor\nPlease note that we can only consider your activities to be lawful if they are proportionate and the purpose of your actions is consistent with the purpose of this Policy. We explicitly do not exclude that any attempt to intentionally or grossly negligently attack our systems with the intent to harm us and/or compromise the confidentiality, integrity or availability of our data may be pursued with legal action.\n\n# Legal\nIf reports/notifications falling within the scope of this Policy are conveyed through a different channel, your report/notification will not be taken into consideration by our company. Instead, you will be directed to the BugBounty Program to submit your report. According to our company policies and procedures, reviews of reports and notifications are carried out by our technical teams only when they are transmitted within the scope of the BugBounty program. Therefore, it is necessary to submit your reports through this program.\n\nDSM reserves the right to modify the terms and conditions of this program and your participation in the program constitutes acceptance of all terms. Please check this website regularly as we update our program terms and conditions of participation periodically. We reserve the right to terminate this program at any time.\n\nThank you for keeping DSM and our users safe! \n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2024-03-05T11:13:14.535Z"},{"id":3709934,"new_policy":"As DSM GRUP DANIŞMANLIK İLETİŞİM VE TİCARET A.Ş. (“DSM”), we highly value security and privacy and  look forward to working with the security community to find security vulnerabilities in order to keep our businesses and customers safe. Off the back of a successful HackerOne Challenge, we are excited to continue leveraging Hacker Powered Security with HackerOne's diverse talent pool.\n\n# Response Targets\nDSM will make its best effort to meet the following SLAs for hackers participating in our program:\n\n| Type of Response | SLA in business days |\n| ------------- | ------------- |\n| First Response | 2 days |\n| Time to Triage | 2 days |\n| Time to Bounty | 14 days |\n| Time to Resolution | depends on severity and complexity |\n\nWe’ll try to keep you informed about our progress throughout the process.\n\n# Disclosure Policy\n* As this is a private program, please do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from DSM\n* Thank you for joining us in supporting ethical and responsible disclosure. By participating in this program, you agree not to share publicly or privately any details or descriptions of your findings with any party.\n* Follow HackerOne's [disclosure guidelines](https://www.hackerone.com/disclosure-guidelines).\n\n#Program Rules\n\nThe program rules for the Bug Bounty program are listed below. In the event of any violation of these rules, we would like to emphasize that performing these actions may result in legal and/or criminal liability for you.\n\n- Social engineering (e.g. phishing, vishing, smishing) is prohibited.\n- Do not perform physical attacks against any DSM facility.\n- Follow HackerOne's disclosure guidelines.\n- Please provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward.\n- Submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact.\n- When duplicates occur, we only award the first report that was received (provided that it can be fully reproduced).\n- Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.\n- Do not compromise or test DSM accounts that are not your own.\n- Do not threaten the DSM and do not try to extort them. Do not act with malicious intent and do not ask for ransom. If you violate this rule, we will exclude you from all current and future programs and none of your reports will be considered. \n- Do not attempt to conduct post-exploitation, including modification or destruction of data, and interruption or degradation of DSM services.\n- Do not perform brute force attacks, denial of service attacks or other attacks that are likely to disrupt, delay or stop DSM's business operations. \n- Reports on outdated versions/builds of in-scope Mobile Apps.\n- It is strictly forbidden for employees, contractors, and members of their immediate families to participate  in the public bounty program or to provide information with an external security researcher to bypass this prohibition. (in which case all parties are ineligible under this program)\n\n\n#Scope\nOur scopes are listed in the assets section below.\n\n- www.trendyol.com (Called from web and mobile apps API will be accepted in scope)\n- m.trendyol.com (Called from web and mobile apps API will be accepted in scope)\n- www.dolap.com (Called from web and mobile apps API will be accepted in scope)\n\n#In-Scope Vulnerability\n| Vulnerability                                               | Severity Range\n|----------                                                  |----------\n|Remote Code Execution                                       |Critical\n|SQL Injection                                               |High - Critical\n|NoSQL Injection                                             |Medium - Critical\n|XXE                                                         |Low - Critical\n|XSS                                                         |Low - Critical\n|Server-Side Request Forgery                                 |Low - Critical\n|Insecure Deserialization                                    |High - Critical\n|Directory Traversal - Local File Inclusion                  |Medium - High\n|Authentication/Authorization Bypass (Broken Access Control) |Medium - High\n|Privilege Escalation                                        |Medium - High\n|Insecure Direct Object Reference                            |Low - Critical\n|Misconfiguration                                            |Low - High\n|Web Cache Deception                                         |Low - High\n|CRLF Injection                                              |Low - Medium\n|Cross Site Request Forgery                                  |Low - Critical\n|Open Redirect                                               |Low\n|Information Disclosure                                      |Low - Critical\n|Request smuggling                                           |Low - High\n|Dependency Confusion                                        |Low - High\n|Mixed Content                                               |Low\n|Server Side Template Injection                              |Low - High\n|Client Side Template Injection                              |Low - Medium\n|Subdomain Takeover                                          |Low - High\n\n#Test Plan\nWeb traffic to and from DSM properties produces petabytes of data every day. When testing, you can make it easier for us to identify your testing traffic against our normal data and the malicious actors out in the world. Please do the following when participating in DSM bug bounty programs:\n\n- Please create accounts using a HackerOne email to help us track security research activity. Where possible, register accounts using your username@wearehackerone.com addresses. Some of our properties will require this to be eligible for a bounty.\n \n- Include a custom HTTP header in all your traffic. Report to us what header you set so we can identify it easily. Our SOC Team is constantly analyzing the traffic so if you don't set this header you might be blocked.\n\n**Format** -\u003e X-Bug-Bounty: hackerone-{username}\n\n**Note:** 0-day and other CVE vulnerabilities may be reported 45 days after initial publication. We have a team dedicated to tracking CVEs as they are released; hosts identified by this team and internally ticketed will not be eligible for bounty.\n\n# Out-of-scope vulnerabilities\n\nWhen reporting vulnerabilities, please consider (1) attack scenario/exploitability, and (2) the security impact of the bug. The following issues are considered out of scope:\n\n- Any non-DSM Applications\n- OTP Rate Limit\n- Issues About Deeplink \n- XSS due to Swagger-UI \n- Clickjacking on pages with no sensitive actions\n- Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive - actions or non-impactful business impact\n- Attacks requiring MITM or physical access to a user's device.\n- Previously known vulnerable libraries without a working Proof of Concept.\n- Comma Separated Values (CSV) injection without demonstrating a vulnerability.\n- Missing best practices in SSL/TLS configuration.\n- Any activity that could lead to the disruption of our service (DoS)\n- Content spoofing and text injection issues without showing a significant attack - vector/without being able to modify HTML/CSS\n- CORS without exploitation\n- Missing security-related HTTP headers which do not lead directly to a vulnerability\n- Rate limiting or brute force issues relying on Cloudflare\n- Missing best practices in Content Security Policy\n- Missing HttpOnly or Secure flags on cookies\n- Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)\n- Vulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]\n- Software version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors)\n- Tabnabbing\n- Open redirect - unless an additional security impact can be demonstrated\n- Host header Injection without a demonstrable impact\n- Issues that require unlikely user interaction\n- Vulnerabilities relating to root detection and cert pinning\n- Vulnerabilities relating to outdated versions of Android\n- Cloudflare public IP leaks\n- Any issues relating to chat features\n- Automated scans and vulnerabilities found by it\n- Performing actions that may negatively affect DSM or its’ customers\n- Conducting any kind of physical attack on DSM’s personnel, property or data centers\n- Exfiltrating data. Please test only the minimum necessary to validate a vulnerability\n- Violating any applicable laws or breaching any applicable agreements in order to discover vulnerabilities\n- Any form of brute force attacks\n- As we have a known issue of missing HTTPOnly flags on session cookies, any vulnerability that leads to Account Take Over under this basis may be capped at a CVSS Medium\n- We'll accept notifications of domain takeover, but they're not eligible for bounty. **Please note that performing the takeover is strictly prohibited.** \n- XML-RPC Vulnerabilities\n- Confidential Information Leakage\n- Missing cookie flags\n- Physical attacks\n- Results of automated scanners\n- Autocomplete attribute on web forms\n- \"Self\" exploitation\n- Flash-based XSS\n- Verbose error pages (without proof of exploitability)\n- Missing Security HTTP Headers (without proof of exploitability)\n- \"Self\" XSS\n- Social Engineering attacks\n- Issues related to networking protocols\n- Reports on outdated version/builds of in-scope Mobile Apps\n- Banner Grabbing\n- Scanner Outputs\n- Password Complexity\n- User Enumeration\n- Host header Injection without a demonstrable impact\n- Stack Traces, Path Disclosure, Directory Listings\n- X-XSS-Protection Header\n- Software Version Disclosure\n- Internal pivoting, scanning, exploiting, or exfiltrating data\n- All Flash-related bugs\n\n# Confidentiality and Protection of Personal Data\nThe “Confidential Information” shall include, any information provided by DSM to the Hacker (Bug Bounty Program Participants) but not be limited to any information, whether in written, oral, electronic, or other tangible forms including, without limitation, the forms currently available and those made available by new technologies in future, regarding the financial, commercial, technical, professional, market and product-related and all kinds of personal information to be disclosed.\n\nIn principle, DSM does not share personal data with Hacker, and only the Hacker can access personal data based on the legal reason that it is compulsory for the performance of the Articles of Association, limited to the performance of the services provided in the Articles of Association.\n\nIf the Hacker accesses personal data that is not necessary for the performance of the Agreement, it will immediately destroy that information and any copies.\n\nIf you encounter user information that is not your own in the course of your research, please stop and report this activity to our team so we can investigate. Please report to us what information was accessed and delete the data. Do not save, copy, transfer, or otherwise use this data. Continuing to access another person’s data may be regarded as evidence of a lack of good faith.\n\n\n# Safe Harbor\nPlease note that we can only consider your activities to be lawful if they are proportionate and the purpose of your actions is consistent with the purpose of this Policy. We explicitly do not exclude that any attempt to intentionally or grossly negligently attack our systems with the intent to harm us and/or compromise the confidentiality, integrity or availability of our data may be pursued with legal action.\n\n# Legal\nIf reports/notifications falling within the scope of this Policy are conveyed through a different channel, your report/notification will not be taken into consideration by our company. Instead, you will be directed to the BugBounty Program to submit your report. According to our company policies and procedures, reviews of reports and notifications are carried out by our technical teams only when they are transmitted within the scope of the BugBounty program. Therefore, it is necessary to submit your reports through this program.\n\nDSM reserves the right to modify the terms and conditions of this program and your participation in the program constitutes acceptance of all terms. Please check this website regularly as we update our program terms and conditions of participation periodically. We reserve the right to terminate this program at any time.\n\nThank you for keeping DSM and our users safe! \n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2023-12-27T12:39:44.662Z"},{"id":3708590,"new_policy":"As DSM GRUP DANIŞMANLIK İLETİŞİM VE TİCARET A.Ş. (“DSM”), we highly value security and privacy and  look forward to working with the security community to find security vulnerabilities in order to keep our businesses and customers safe. Off the back of a successful HackerOne Challenge, we are excited to continue leveraging Hacker Powered Security with HackerOne's diverse talent pool.\n\n# Response Targets\nDSM will make its best effort to meet the following SLAs for hackers participating in our program:\n\n| Type of Response | SLA in business days |\n| ------------- | ------------- |\n| First Response | 2 days |\n| Time to Triage | 2 days |\n| Time to Bounty | 14 days |\n| Time to Resolution | depends on severity and complexity |\n\nWe’ll try to keep you informed about our progress throughout the process.\n\n# Disclosure Policy\n* As this is a private program, please do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from DSM\n* Thank you for joining us in supporting ethical and responsible disclosure. By participating in this program, you agree not to share publicly or privately any details or descriptions of your findings with any party.\n* Follow HackerOne's [disclosure guidelines](https://www.hackerone.com/disclosure-guidelines).\n\n#Program Rules\n\nThe program rules for the Bug Bounty program are listed below. In the event of any violation of these rules, we would like to emphasize that performing these actions may result in legal and/or criminal liability for you.\n\n- Social engineering (e.g. phishing, vishing, smishing) is prohibited.\n- Do not perform physical attacks against any DSM facility.\n- Follow HackerOne's disclosure guidelines.\n- Please provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward.\n- Submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact.\n- When duplicates occur, we only award the first report that was received (provided that it can be fully reproduced).\n- Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.\n- Do not compromise or test DSM accounts that are not your own.\n- Do not threaten the DSM and do not try to extort them. Do not act with malicious intent and do not ask for ransom. If you violate this rule, we will exclude you from all current and future programs and none of your reports will be considered. \n- Do not attempt to conduct post-exploitation, including modification or destruction of data, and interruption or degradation of DSM services.\n- Do not perform brute force attacks, denial of service attacks or other attacks that are likely to disrupt, delay or stop DSM's business operations. \n- Reports on outdated versions/builds of in-scope Mobile Apps.\n- It is strictly forbidden for employees, contractors, and members of their immediate families to participate  in the public bounty program or to provide information with an external security researcher to bypass this prohibition. (in which case all parties are ineligible under this program)\n\n\n#Scope\nOur scopes are listed in the assets section below.\n\n- www.trendyol.com (Called from web and mobile apps API will be accepted in scope)\n- m.trendyol.com (Called from web and mobile apps API will be accepted in scope)\n- www.dolap.com (Called from web and mobile apps API will be accepted in scope)\n- www.trendyol-milla.com (Called from web apps API will be accepted in scope)\n\n#In-Scope Vulnerability\n| Vulnerability                                               | Severity Range\n|----------                                                  |----------\n|Remote Code Execution                                       |Critical\n|SQL Injection                                               |High - Critical\n|NoSQL Injection                                             |Medium - Critical\n|XXE                                                         |Low - Critical\n|XSS                                                         |Low - Critical\n|Server-Side Request Forgery                                 |Low - Critical\n|Insecure Deserialization                                    |High - Critical\n|Directory Traversal - Local File Inclusion                  |Medium - High\n|Authentication/Authorization Bypass (Broken Access Control) |Medium - High\n|Privilege Escalation                                        |Medium - High\n|Insecure Direct Object Reference                            |Low - Critical\n|Misconfiguration                                            |Low - High\n|Web Cache Deception                                         |Low - High\n|CRLF Injection                                              |Low - Medium\n|Cross Site Request Forgery                                  |Low - Critical\n|Open Redirect                                               |Low\n|Information Disclosure                                      |Low - Critical\n|Request smuggling                                           |Low - High\n|Dependency Confusion                                        |Low - High\n|Mixed Content                                               |Low\n|Server Side Template Injection                              |Low - High\n|Client Side Template Injection                              |Low - Medium\n|Subdomain Takeover                                          |Low - High\n\n#Test Plan\nWeb traffic to and from DSM properties produces petabytes of data every day. When testing, you can make it easier for us to identify your testing traffic against our normal data and the malicious actors out in the world. Please do the following when participating in DSM bug bounty programs:\n\n- Please create accounts using a HackerOne email to help us track security research activity. Where possible, register accounts using your username@wearehackerone.com addresses. Some of our properties will require this to be eligible for a bounty.\n \n- Include a custom HTTP header in all your traffic. Report to us what header you set so we can identify it easily. Our SOC Team is constantly analyzing the traffic so if you don't set this header you might be blocked.\n\n**Format** -\u003e X-Bug-Bounty: hackerone-{username}\n\n**Note:** 0-day and other CVE vulnerabilities may be reported 45 days after initial publication. We have a team dedicated to tracking CVEs as they are released; hosts identified by this team and internally ticketed will not be eligible for bounty.\n\n# Out-of-scope vulnerabilities\n\nWhen reporting vulnerabilities, please consider (1) attack scenario/exploitability, and (2) the security impact of the bug. The following issues are considered out of scope:\n\n- Any non-DSM Applications\n- OTP Rate Limit\n- Issues About Deeplink \n- XSS due to Swagger-UI \n- Clickjacking on pages with no sensitive actions\n- Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive - actions or non-impactful business impact\n- Attacks requiring MITM or physical access to a user's device.\n- Previously known vulnerable libraries without a working Proof of Concept.\n- Comma Separated Values (CSV) injection without demonstrating a vulnerability.\n- Missing best practices in SSL/TLS configuration.\n- Any activity that could lead to the disruption of our service (DoS)\n- Content spoofing and text injection issues without showing a significant attack - vector/without being able to modify HTML/CSS\n- CORS without exploitation\n- Missing security-related HTTP headers which do not lead directly to a vulnerability\n- Rate limiting or brute force issues relying on Cloudflare\n- Missing best practices in Content Security Policy\n- Missing HttpOnly or Secure flags on cookies\n- Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)\n- Vulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]\n- Software version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors)\n- Tabnabbing\n- Open redirect - unless an additional security impact can be demonstrated\n- Host header Injection without a demonstrable impact\n- Issues that require unlikely user interaction\n- Vulnerabilities relating to root detection and cert pinning\n- Vulnerabilities relating to outdated versions of Android\n- Cloudflare public IP leaks\n- Any issues relating to chat features\n- Automated scans and vulnerabilities found by it\n- Performing actions that may negatively affect DSM or its’ customers\n- Conducting any kind of physical attack on DSM’s personnel, property or data centers\n- Exfiltrating data. Please test only the minimum necessary to validate a vulnerability\n- Violating any applicable laws or breaching any applicable agreements in order to discover vulnerabilities\n- Any form of brute force attacks\n- As we have a known issue of missing HTTPOnly flags on session cookies, any vulnerability that leads to Account Take Over under this basis may be capped at a CVSS Medium\n- We'll accept notifications of domain takeover, but they're not eligible for bounty. **Please note that performing the takeover is strictly prohibited.** \n- XML-RPC Vulnerabilities\n- Confidential Information Leakage\n- Missing cookie flags\n- Physical attacks\n- Results of automated scanners\n- Autocomplete attribute on web forms\n- \"Self\" exploitation\n- Flash-based XSS\n- Verbose error pages (without proof of exploitability)\n- Missing Security HTTP Headers (without proof of exploitability)\n- \"Self\" XSS\n- Social Engineering attacks\n- Issues related to networking protocols\n- Reports on outdated version/builds of in-scope Mobile Apps\n- Banner Grabbing\n- Scanner Outputs\n- Password Complexity\n- User Enumeration\n- Host header Injection without a demonstrable impact\n- Stack Traces, Path Disclosure, Directory Listings\n- X-XSS-Protection Header\n- Software Version Disclosure\n- Internal pivoting, scanning, exploiting, or exfiltrating data\n- All Flash-related bugs\n\n# Confidentiality and Protection of Personal Data\nThe “Confidential Information” shall include, any information provided by DSM to the Hacker (Bug Bounty Program Participants) but not be limited to any information, whether in written, oral, electronic, or other tangible forms including, without limitation, the forms currently available and those made available by new technologies in future, regarding the financial, commercial, technical, professional, market and product-related and all kinds of personal information to be disclosed.\n\nIn principle, DSM does not share personal data with Hacker, and only the Hacker can access personal data based on the legal reason that it is compulsory for the performance of the Articles of Association, limited to the performance of the services provided in the Articles of Association.\n\nIf the Hacker accesses personal data that is not necessary for the performance of the Agreement, it will immediately destroy that information and any copies.\n\nIf you encounter user information that is not your own in the course of your research, please stop and report this activity to our team so we can investigate. Please report to us what information was accessed and delete the data. Do not save, copy, transfer, or otherwise use this data. Continuing to access another person’s data may be regarded as evidence of a lack of good faith.\n\n\n# Safe Harbor\nPlease note that we can only consider your activities to be lawful if they are proportionate and the purpose of your actions is consistent with the purpose of this Policy. We explicitly do not exclude that any attempt to intentionally or grossly negligently attack our systems with the intent to harm us and/or compromise the confidentiality, integrity or availability of our data may be pursued with legal action.\n\n# Legal\nIf reports/notifications falling within the scope of this Policy are conveyed through a different channel, your report/notification will not be taken into consideration by our company. Instead, you will be directed to the BugBounty Program to submit your report. According to our company policies and procedures, reviews of reports and notifications are carried out by our technical teams only when they are transmitted within the scope of the BugBounty program. Therefore, it is necessary to submit your reports through this program.\n\nDSM reserves the right to modify the terms and conditions of this program and your participation in the program constitutes acceptance of all terms. Please check this website regularly as we update our program terms and conditions of participation periodically. We reserve the right to terminate this program at any time.\n\nThank you for keeping DSM and our users safe! \n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2023-12-05T06:04:42.417Z"},{"id":3683817,"new_policy":"DSM GRUP DANIŞMANLIK İLETİŞİM VE TİCARET A.Ş. (“Trendyol Group” or “Trendyol”) is the largest e-commerce platform in Turkey, and looks forward to working with the security community to find security vulnerabilities in order to keep our businesses and customers safe. Off the back of a successful HackerOne Challenge, we are excited to continue leveraging Hacker Powered Security with HackerOne's diverse talent pool.\n\n# Response Targets\nTrendyol Group will make its best effort to meet the following SLAs for hackers participating in our program:\n\n| Type of Response | SLA in business days |\n| ------------- | ------------- |\n| First Response | 2 days |\n| Time to Triage | 2 days |\n| Time to Bounty | 14 days |\n| Time to Resolution | depends on severity and complexity |\n\nWe’ll try to keep you informed about our progress throughout the process.\n\n# Disclosure Policy\n* As this is a private program, please do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from Trendyol Group\n* Thank you for joining us in supporting ethical and responsible disclosure. By participating in this program, you agree not to share publicly or privately any details or descriptions of your findings with any party.\n* Follow HackerOne's [disclosure guidelines](https://www.hackerone.com/disclosure-guidelines).\n\n#Program Rules\n- Social engineering (e.g. phishing, vishing, smishing) is prohibited.\n- Do not perform physical attacks against any Trendyol facility.\n- Follow HackerOne's disclosure guidelines.\n- Please provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward.\n- Submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact.\n- When duplicates occur, we only award the first report that was received (provided that it can be fully reproduced).\n- Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.\n- Do not compromise or test Trendyol Group accounts that are not your own.\n- Do not threaten the Trendyol Group and do not try to extort them. Do not act with malicious intent and do not ask for ransom. If you violate this rule, we will exclude you from all current and future programs and none of your reports will be considered. \n- Do not attempt to conduct post-exploitation, including modification or destruction of data, and interruption or degradation of Trendyol Group services.\n- Do not perform brute force attacks, denial of service attacks or other attacks that are likely to disrupt, delay or stop Trendyol Group's business operations. \n- Reports on outdated versions/builds of in-scope Mobile Apps.\n- It is strictly forbidden for employees, contractors, and members of their immediate families to participate  in the public bounty program or to provide information with an external security researcher to bypass this prohibition. (in which case all parties are ineligible under this program)\n\n\n#Scope\nOur scopes are listed in the assets section below.\n\n- www.trendyol.com (Called from web and mobile apps API will be accepted in scope)\n- m.trendyol.com (Called from web and mobile apps API will be accepted in scope)\n- www.dolap.com (Called from web and mobile apps API will be accepted in scope)\n\n#In-Scope Vulnerability\n| Vulnerability                                               | Severity Range\n|----------                                                  |----------\n|Remote Code Execution                                       |Critical\n|SQL Injection                                               |High - Critical\n|NoSQL Injection                                             |Medium - Critical\n|XXE                                                         |Low - Critical\n|XSS                                                         |Low - Critical\n|Server-Side Request Forgery                                 |Low - Critical\n|Insecure Deserialization                                    |High - Critical\n|Directory Traversal - Local File Inclusion                  |Medium - High\n|Authentication/Authorization Bypass (Broken Access Control) |Medium - High\n|Privilege Escalation                                        |Medium - High\n|Insecure Direct Object Reference                            |Low - Critical\n|Misconfiguration                                            |Low - High\n|Web Cache Deception                                         |Low - High\n|CRLF Injection                                              |Low - Medium\n|Cross Site Request Forgery                                  |Low - Critical\n|Open Redirect                                               |Low\n|Information Disclosure                                      |Low - Critical\n|Request smuggling                                           |Low - High\n|Dependency Confusion                                        |Low - High\n|Mixed Content                                               |Low\n|Server Side Template Injection                              |Low - High\n|Client Side Template Injection                              |Low - Medium\n|Subdomain Takeover                                          |Low - High\n\n#Test Plan\nWeb traffic to and from Trendyol properties produces petabytes of data every day. When testing, you can make it easier for us to identify your testing traffic against our normal data and the malicious actors out in the world. Please do the following when participating in Trendyol bug bounty programs:\n\n- Please create accounts using a HackerOne email to help us track security research activity. Where possible, register accounts using your username@wearehackerone.com addresses. Some of our properties will require this to be eligible for a bounty.\n \n- Include a custom HTTP header in all your traffic. Report to us what header you set so we can identify it easily. Our SOC Team is constantly analyzing the traffic so if you don't set this header you might be blocked.\n\n**Format** -\u003e X-Bug-Bounty: hackerone-{username}\n\n**Note:** 0-day and other CVE vulnerabilities may be reported 45 days after initial publication. We have a team dedicated to tracking CVEs as they are released; hosts identified by this team and internally ticketed will not be eligible for bounty.\n\n# Out-of-scope vulnerabilities\n\nWhen reporting vulnerabilities, please consider (1) attack scenario/exploitability, and (2) the security impact of the bug. The following issues are considered out of scope:\n\n- Any non-Trendyol Applications\n- OTP Rate Limit\n- Issues About Deeplink \n- XSS due to Swagger-UI \n- Clickjacking on pages with no sensitive actions\n- Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive - actions or non-impactful business impact\n- Attacks requiring MITM or physical access to a user's device.\n- Previously known vulnerable libraries without a working Proof of Concept.\n- Comma Separated Values (CSV) injection without demonstrating a vulnerability.\n- Missing best practices in SSL/TLS configuration.\n- Any activity that could lead to the disruption of our service (DoS)\n- Content spoofing and text injection issues without showing a significant attack - vector/without being able to modify HTML/CSS\n- CORS without exploitation\n- Missing security-related HTTP headers which do not lead directly to a vulnerability\n- Rate limiting or brute force issues relying on Cloudflare\n- Missing best practices in Content Security Policy\n- Missing HttpOnly or Secure flags on cookies\n- Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)\n- Vulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]\n- Software version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors)\n- Tabnabbing\n- Open redirect - unless an additional security impact can be demonstrated\n- Host header Injection without a demonstrable impact\n- Issues that require unlikely user interaction\n- Vulnerabilities relating to root detection and cert pinning\n- Vulnerabilities relating to outdated versions of Android\n- Cloudflare public IP leaks\n- Any issues relating to chat features\n- Automated scans and vulnerabilities found by it\n- Performing actions that may negatively affect Trendyol or its’ customers\n- Conducting any kind of physical attack on Trendyol’s personnel, property or data centers\n- Exfiltrating data. Please test only the minimum necessary to validate a vulnerability\n- Violating any applicable laws or breaching any applicable agreements in order to discover vulnerabilities\n- Any form of brute force attacks\n- As we have a known issue of missing HTTPOnly flags on session cookies, any vulnerability that leads to Account Take Over under this basis may be capped at a CVSS Medium\n- We'll accept notifications of domain takeover, but they're not eligible for bounty. **Please note that performing the takeover is strictly prohibited.** \n- XML-RPC Vulnerabilities\n- Confidential Information Leakage\n- Missing cookie flags\n- Physical attacks\n- Results of automated scanners\n- Autocomplete attribute on web forms\n- \"Self\" exploitation\n- Flash-based XSS\n- Verbose error pages (without proof of exploitability)\n- Missing Security HTTP Headers (without proof of exploitability)\n- \"Self\" XSS\n- Social Engineering attacks\n- Issues related to networking protocols\n- Reports on outdated version/builds of in-scope Mobile Apps\n- Banner Grabbing\n- Scanner Outputs\n- Password Complexity\n- User Enumeration\n- Host header Injection without a demonstrable impact\n- Stack Traces, Path Disclosure, Directory Listings\n- X-XSS-Protection Header\n- Software Version Disclosure\n- Internal pivoting, scanning, exploiting, or exfiltrating data\n- All Flash-related bugs\n\n# Confidentiality and Protection of Personal Data\nThe “Confidential Information” shall include, any information provided by Trendyol Group to the Hacker (Bug Bounty Program Participants) but not be limited to any information, whether in written, oral, electronic, or other tangible forms including, without limitation, the forms currently available and those made available by new technologies in future, regarding the financial, commercial, technical, professional, market and product-related and all kinds of personal information to be disclosed.\n\nIn principle, Trendyol Group does not share personal data with Hacker, and only the Hacker can access personal data based on the legal reason that it is compulsory for the performance of the Articles of Association, limited to the performance of the services provided in the Articles of Association.\n\nIf the Hacker accesses personal data that is not necessary for the performance of the Agreement, it will immediately destroy that information and any copies.\n\nIf you encounter user information that is not your own in the course of your research, please stop and report this activity to our team so we can investigate. Please report to us what information was accessed and delete the data. Do not save, copy, transfer, or otherwise use this data. Continuing to access another person’s data may be regarded as evidence of a lack of good faith.\n\n\n# Safe Harbor\nPlease note that we can only consider your activities to be lawful if they are proportionate and the purpose of your actions is consistent with the purpose of this Policy. We explicitly do not exclude that any attempt to intentionally or grossly negligently attack our systems with the intent to harm us and/or compromise the confidentiality, integrity or availability of our data may be pursued with legal action.\n\n# Legal\nTrendyol reserves the right to modify the terms and conditions of this program and your participation in the program constitutes acceptance of all terms. Please check this website regularly as we update our program terms and conditions of participation periodically. We reserve the right to terminate this program at any time.\n\nThank you for keeping Trendyol Group and our users safe! \n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2023-02-19T19:03:35.636Z"},{"id":3679662,"new_policy":"DSM GRUP DANIŞMANLIK İLETİŞİM VE TİCARET A.Ş. (“Trendyol Group” or “Trendyol”) is the largest e-commerce platform in Turkey, and looks forward to working with the security community to find security vulnerabilities in order to keep our businesses and customers safe. Off the back of a successful HackerOne Challenge, we are excited to continue leveraging Hacker Powered Security with HackerOne's diverse talent pool.\n\n# Response Targets\nTrendyol Group will make its best effort to meet the following SLAs for hackers participating in our program:\n\n| Type of Response | SLA in business days |\n| ------------- | ------------- |\n| First Response | 2 days |\n| Time to Triage | 2 days |\n| Time to Bounty | 14 days |\n| Time to Resolution | depends on severity and complexity |\n\nWe’ll try to keep you informed about our progress throughout the process.\n\n# Disclosure Policy\n* As this is a private program, please do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from Trendyol Group\n* Thank you for joining us in supporting ethical and responsible disclosure. By participating in this program, you agree not to share publicly or privately any details or descriptions of your findings with any party.\n* Follow HackerOne's [disclosure guidelines](https://www.hackerone.com/disclosure-guidelines).\n\n#Program Rules\n- Social engineering (e.g. phishing, vishing, smishing) is prohibited.\n- Do not perform physical attacks against any Trendyol facility.\n- Follow HackerOne's disclosure guidelines.\n- Please provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward.\n- Submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact.\n- When duplicates occur, we only award the first report that was received (provided that it can be fully reproduced).\n- Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.\n- Do not compromise or test Trendyol Group accounts that are not your own.\n- Do not threaten the Trendyol Group and do not try to extort them. Do not act with malicious intent and do not ask for ransom. If you violate this rule, we will exclude you from all current and future programs and none of your reports will be considered. \n- Do not attempt to conduct post-exploitation, including modification or destruction of data, and interruption or degradation of Trendyol Group services.\n- Do not perform brute force attacks, denial of service attacks or other attacks that are likely to disrupt, delay or stop Trendyol Group's business operations. \n- Reports on outdated versions/builds of in-scope Mobile Apps.\n- It is strictly forbidden for employees, contractors, and members of their immediate families to participate  in the public bounty program or to provide information with an external security researcher to bypass this prohibition. (in which case all parties are ineligible under this program)\n\n\n#Scope\nOur scopes are listed in the assets section below.\n\n- www.trendyol.com (Called from web and mobile apps API will be accepted in scope)\n- m.trendyol.com (Called from web and mobile apps API will be accepted in scope)\n- www.dolap.com (Called from web and mobile apps API will be accepted in scope)\n\n#Test Plan\nWeb traffic to and from Trendyol properties produces petabytes of data every day. When testing, you can make it easier for us to identify your testing traffic against our normal data and the malicious actors out in the world. Please do the following when participating in Trendyol bug bounty programs:\n\n- Please create accounts using a HackerOne email to help us track security research activity. Where possible, register accounts using your username@wearehackerone.com addresses. Some of our properties will require this to be eligible for a bounty.\n \n- Include a custom HTTP header in all your traffic. Report to us what header you set so we can identify it easily. Our SOC Team is constantly analyzing the traffic so if you don't set this header you might be blocked.\n\n**Format** -\u003e X-Bug-Bounty: hackerone-{username}\n\n# Out-of-scope vulnerabilities\n\nWhen reporting vulnerabilities, please consider (1) attack scenario/exploitability, and (2) the security impact of the bug. The following issues are considered out of scope:\n\n- Issues About Deeplink \n- XSS due to Swagger-UI \n- Clickjacking on pages with no sensitive actions\n- Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive - actions or non-impactful business impact\n- Attacks requiring MITM or physical access to a user's device.\n- Previously known vulnerable libraries without a working Proof of Concept.\n- Comma Separated Values (CSV) injection without demonstrating a vulnerability.\n- Missing best practices in SSL/TLS configuration.\n- Any activity that could lead to the disruption of our service (DoS)\n- Content spoofing and text injection issues without showing a significant attack - vector/without being able to modify HTML/CSS\n- CORS without exploitation\n- Missing security-related HTTP headers which do not lead directly to a vulnerability\n- Rate limiting or brute force issues relying on Cloudflare\n- Missing best practices in Content Security Policy\n- Missing HttpOnly or Secure flags on cookies\n- Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)\n- Vulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]\n- Software version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors)\n- Public Zero-day vulnerabilities that have had an official patch for less than 1 month will be awarded on a case by case basis\n- Tabnabbing\n- Open redirect - unless an additional security impact can be demonstrated\n- Host header Injection without a demonstrable impact\n- Issues that require unlikely user interaction\n- Vulnerabilities relating to root detection and cert pinning\n- Vulnerabilities relating to outdated versions of Android\n- Cloudflare public IP leaks\n- Any issues relating to chat features\n- Automated scans and vulnerabilities found by it\n- Performing actions that may negatively affect Trendyol or its’ customers\n- Conducting any kind of physical attack on Trendyol’s personnel, property or data centers\n- Exfiltrating data. Please test only the minimum necessary to validate a vulnerability\n- Violating any applicable laws or breaching any applicable agreements in order to discover vulnerabilities\n- Any form of brute force attacks\n- As we have a known issue of missing HTTPOnly flags on session cookies, any vulnerability that leads to Account Take Over under this basis may be capped at a CVSS Medium\n- We'll accept notifications of domain takeover, but they're not eligible for bounty. **Please note that performing the takeover is strictly prohibited.** \n- XML-RPC Vulnerabilities\n\n# Confidentiality and Protection of Personal Data\nThe “Confidential Information” shall include, any information provided by Trendyol Group to the Hacker (Bug Bounty Program Participants) but not be limited to any information, whether in written, oral, electronic, or other tangible forms including, without limitation, the forms currently available and those made available by new technologies in future, regarding the financial, commercial, technical, professional, market and product-related and all kinds of personal information to be disclosed.\n\nIn principle, Trendyol Group does not share personal data with Hacker, and only the Hacker can access personal data based on the legal reason that it is compulsory for the performance of the Articles of Association, limited to the performance of the services provided in the Articles of Association.\n\nIf the Hacker accesses personal data that is not necessary for the performance of the Agreement, it will immediately destroy that information and any copies.\n\nIf you encounter user information that is not your own in the course of your research, please stop and report this activity to our team so we can investigate. Please report to us what information was accessed and delete the data. Do not save, copy, transfer, or otherwise use this data. Continuing to access another person’s data may be regarded as evidence of a lack of good faith.\n\n\n# Safe Harbor\nPlease note that we can only consider your activities to be lawful if they are proportionate and the purpose of your actions is consistent with the purpose of this Policy. We explicitly do not exclude that any attempt to intentionally or grossly negligently attack our systems with the intent to harm us and/or compromise the confidentiality, integrity or availability of our data may be pursued with legal action.\n\n# Legal\nTrendyol reserves the right to modify the terms and conditions of this program and your participation in the program constitutes acceptance of all terms. Please check this website regularly as we update our program terms and conditions of participation periodically. We reserve the right to terminate this program at any time.\n\nThank you for keeping Trendyol Group and our users safe! \n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2022-11-08T10:11:50.637Z"},{"id":3679661,"new_policy":"DSM GRUP DANIŞMANLIK İLETİŞİM VE TİCARET A.Ş. (“Trendyol Group” or “Trendyol”) is the largest e-commerce platform in Turkey, and looks forward to working with the security community to find security vulnerabilities in order to keep our businesses and customers safe. Off the back of a successful HackerOne Challenge, we are excited to continue leveraging Hacker Powered Security with HackerOne's diverse talent pool.\n\n# Response Targets\nTrendyol Group will make its best effort to meet the following SLAs for hackers participating in our program:\n\n| Type of Response | SLA in business days |\n| ------------- | ------------- |\n| First Response | 2 days |\n| Time to Triage | 2 days |\n| Time to Bounty | 14 days |\n| Time to Resolution | depends on severity and complexity |\n\nWe’ll try to keep you informed about our progress throughout the process.\n\n# Disclosure Policy\n* As this is a private program, please do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from Trendyol Group\n* Thank you for joining us in supporting ethical and responsible disclosure. By participating in this program, you agree not to share publicly or privately any details or descriptions of your findings with any party.\n* Follow HackerOne's [disclosure guidelines](https://www.hackerone.com/disclosure-guidelines).\n\n#Program Rules\n- Social engineering (e.g. phishing, vishing, smishing) is prohibited.\n- Do not perform physical attacks against any Trendyol facility.\n- Follow HackerOne's disclosure guidelines.\n- Please provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward.\n- Submit one vulnerability per report, unless you need to chain vulnerabilities to provide impact.\n- When duplicates occur, we only award the first report that was received (provided that it can be fully reproduced).\n- Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.\n- Do not compromise or test Trendyol Group accounts that are not your own.\n- Do not threaten the Trendyol Group and do not try to extort them. Do not act with malicious intent and do not ask for ransom. If you violate this rule, we will exclude you from all current and future programs and none of your reports will be considered. \n- Do not attempt to conduct post-exploitation, including modification or destruction of data, and interruption or degradation of Trendyol Group services.\n- Do not perform brute force attacks, denial of service attacks or other attacks that are likely to disrupt, delay or stop Trendyol Group's business operations. \n- Reports on outdated versions/builds of in-scope Mobile Apps.\n- It is strictly forbidden for employees, contractors, and members of their immediate families to participate  in the public bounty program or to provide information with an external security researcher to bypass this prohibition. (in which case all parties are ineligible under this program)\n\n\n#Scope\nOur scopes are listed in the assets section below.\n\n- www.trendyol.com (Called from web and mobile apps API will be accepted in scope)\n- m.trendyol.com (Called from web and mobile apps API will be accepted in scope)\n- www.dolap.com (Called from web and mobile apps API will be accepted in scope)\n\n#Test Plan\nWeb traffic to and from Trendyol properties produces petabytes of data every day. When testing, you can make it easier for us to identify your testing traffic against our normal data and the malicious actors out in the world. Please do the following when participating in Trendyol bug bounty programs:\n\n- Please create accounts using a HackerOne email to help us track security research activity. Where possible, register accounts using your username@wearehackerone.com addresses. Some of our properties will require this to be eligible for a bounty.\n \n- Include a custom HTTP header in all your traffic. Report to us what header you set so we can identify it easily. Our SOC Team is constantly analyzing the traffic so if you don't set this header you might be blocked.\n\n**Format** -\u003e X-Bug-Bounty: hackerone-{username}\n\n# Out-of-scope vulnerabilities\n\nWhen reporting vulnerabilities, please consider (1) attack scenario/exploitability, and (2) the security impact of the bug. The following issues are considered out of scope:\n\n- Issues About Deeplink \n- XSS due to Swagger-UI \n- Clickjacking on pages with no sensitive actions\n- Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive - actions or non-impactful business impact\n- Attacks requiring MITM or physical access to a user's device.\n- Previously known vulnerable libraries without a working Proof of Concept.\n- Comma Separated Values (CSV) injection without demonstrating a vulnerability.\n- Missing best practices in SSL/TLS configuration.\n- Any activity that could lead to the disruption of our service (DoS)\n- Content spoofing and text injection issues without showing a significant attack - vector/without being able to modify HTML/CSS\n- CORS without exploitation\n- Missing security-related HTTP headers which do not lead directly to a vulnerability\n- Rate limiting or brute force issues relying on Cloudflare\n- Missing best practices in Content Security Policy\n- Missing HttpOnly or Secure flags on cookies\n- Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)\n- Vulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]\n- Software version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors)\n- Public Zero-day vulnerabilities that have had an official patch for less than 1 month will be awarded on a case by case basis\n- Tabnabbing\n- Open redirect - unless an additional security impact can be demonstrated\n- Host header Injection without a demonstrable impact\n- Issues that require unlikely user interaction\n- Vulnerabilities relating to root detection and cert pinning\n- Vulnerabilities relating to outdated versions of Android\n- Cloudflare public IP leaks\n- Any issues relating to chat features\n- Automated scans and vulnerabilities found by it\n- Performing actions that may negatively affect Trendyol or its’ customers\n- Conducting any kind of physical attack on Trendyol’s personnel, property or data centers\n- Exfiltrating data. Please test only the minimum necessary to validate a vulnerability\n- Violating any applicable laws or breaching any applicable agreements in order to discover vulnerabilities\n- Any form of brute force attacks\n- As we have a known issue of missing HTTPOnly flags on session cookies, any vulnerability that leads to Account Take Over under this basis may be capped at a CVSS Medium\n- We'll accept notifications of domain takeover, but they're not eligible for bounty. **Please note that performing the takeover is strictly prohibited.** \n- XML-RPC Vulnerabilities\n\n# Confidentiality and Protection of Personal Data\nThe “Confidential Information” shall include, any information provided by Trendyol Group to the Hacker (Bug Bounty Program Participants) but not be limited to any information, whether in written, oral, electronic, or other tangible forms including, without limitation, the forms currently available and those made available by new technologies in future, regarding the financial, commercial, technical, professional, market and product-related and all kinds of personal information to be disclosed.\n\nIn principle, Trendyol Group does not share personal data with Hacker, and only the Hacker can access personal data based on the legal reason that it is compulsory for the performance of the Articles of Association, limited to the performance of the services provided in the Articles of Association.\n\nIf the Hacker accesses personal data that is not necessary for the performance of the Agreement, it will immediately destroy that information and any copies.\n\nIf you encounter user information that is not your own in the course of your research, please stop and report this activity to our team so we can investigate. Please report to us what information was accessed and delete the data. Do not save, copy, transfer, or otherwise use this data. Continuing to access another person’s data may be regarded as evidence of a lack of good faith.\n\n\n# Safe Harbor\nPlease note that we can only consider your activities to be lawful if they are proportionate and the purpose of your actions is consistent with the purpose of this Policy. We explicitly do not exclude that any attempt to intentionally or grossly negligently attack our systems with the intent to harm us and/or compromise the confidentiality, integrity or availability of our data may be pursued with legal action.\n\n#Legal\nTrendyol reserves the right to modify the terms and conditions of this program and your participation in the program constitutes acceptance of all terms. Please check this website regularly as we update our program terms and conditions of participation periodically. We reserve the right to terminate this program at any time.\n\nThank you for keeping Trendyol Group and our users safe! \n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2022-11-08T10:11:18.012Z"},{"id":3676134,"new_policy":"Trendyol Group is the largest e-commerce platform in Turkey, and looks forward to working with the security community to find security vulnerabilities in order to keep our businesses and customers safe. Off the back of a successful HackerOne Challenge, we are excited to continue leveraging Hacker Powered Security with HackerOne's diverse talent pool.\n\n# Response Targets\nTrendyol Group will make its best effort to meet the following SLAs for hackers participating in our program:\n\n| Type of Response | SLA in business days |\n| ------------- | ------------- |\n| First Response | 2 days |\n| Time to Triage | 2 days |\n| Time to Bounty | 14 days |\n| Time to Resolution | depends on severity and complexity |\n\nWe’ll try to keep you informed about our progress throughout the process.\n\n# Disclosure Policy\n* As this is a private program, please do not discuss this program or any vulnerabilities (even resolved ones) outside of the program without express consent from the organization.\n* Follow HackerOne's [disclosure guidelines](https://www.hackerone.com/disclosure-guidelines).\n\n#Program Rules\n- Social engineering (e.g. phishing, vishing, smishing) is prohibited.\n- Follow HackerOne's disclosure guidelines.\n- Please provide detailed reports with reproducible steps. If the report is not detailed enough to reproduce the issue, the issue will not be eligible for a reward.\n- Submit one vulnerability per the report, unless you need to chain vulnerabilities to provide impact.\n- When duplicates occur, we only award the first report that was received (provided that it can be fully reproduced).\n- Multiple vulnerabilities caused by one underlying issue will be awarded one bounty.\n- Do not compromise or test Trendyol accounts that are not your own.\n- Do not attempt to conduct post-exploitation, including modification or destruction of data, and interruption or degradation of Trendyol services.\n- Reports on outdated versions/builds of in-scope Mobile Apps.\n\n#Scope\nOur scopes are listed in the assets section below.\n\n- www.trendyol.com (Called from web and mobile apps API will be accepted in scope)\n- m.trendyol.com (Called from web and mobile apps API will be accepted in scope)\n- www.dolap.com (Called from web and mobile apps API will be accepted in scope)\n\n#Test Plan\nWeb traffic to and from Trendyol properties produces petabytes of data every day. When testing, you can make it easier for us to identify your testing traffic against our normal data and the malicious actors out in the world. Please do the following when participating in Trendyol bug bounty programs:\n\n- Please create accounts using a HackerOne email to help us track security research activity. Where possible, register accounts using your username@wearehackerone.com addresses. Some of our properties will require this to be eligible for a bounty.\n \n- Include a custom HTTP header in all your traffic. Report to us what header you set so we can identify it easily. Our SOC Team is constantly analyzing the traffic so if you don't set this header you might be blocked.\n\n**Format** -\u003e X-Bug-Bounty: hackerone-{username}\n\n# Out-of-scope vulnerabilities\n\nWhen reporting vulnerabilities, please consider (1) attack scenario/exploitability, and (2) the security impact of the bug. The following issues are considered out of scope:\n\n- Issues About Deeplink \n- XSS due to Swagger-UI \n- Clickjacking on pages with no sensitive actions\n- Cross-Site Request Forgery (CSRF) on unauthenticated forms or forms with no sensitive - actions or non-impactful business impact\n- Attacks requiring MITM or physical access to a user's device.\n- Previously known vulnerable libraries without a working Proof of Concept.\n- Comma Separated Values (CSV) injection without demonstrating a vulnerability.\n- Missing best practices in SSL/TLS configuration.\n- Any activity that could lead to the disruption of our service (DoS)\n- Content spoofing and text injection issues without showing a significant attack - vector/without being able to modify HTML/CSS\n- CORS without exploitation\n- Missing security-related HTTP headers which do not lead directly to a vulnerability\n- Rate limiting or brute force issues relying on Cloudflare\n- Missing best practices in Content Security Policy\n- Missing HttpOnly or Secure flags on cookies\n- Missing email best practices (Invalid, incomplete or missing SPF/DKIM/DMARC records, etc.)\n- Vulnerabilities only affecting users of outdated or unpatched browsers [Less than 2 stable versions behind the latest released stable version]\n- Software version disclosure / Banner identification issues / Descriptive error messages or headers (e.g. stack traces, application or server errors)\n- Public Zero-day vulnerabilities that have had an official patch for less than 1 month will be awarded on a case by case basis\n- Tabnabbing\n- Open redirect - unless an additional security impact can be demonstrated\n- Host header Injection without a demonstrable impact\n- Issues that require unlikely user interaction\n- Vulnerabilities relating to root detection and cert pinning\n- Vulnerabilities relating to outdated versions of Android\n- Cloudflare public IP leaks\n- Any issues relating to chat features\n- Automated scans and vulnerabilities found by it\n- Performing actions that may negatively affect Trendyol or its’ customers\n- Conducting any kind of physical attack on Trendyol’s personnel, property or data centers\n- Exfiltrating data. Please test only the minimum necessary to validate a vulnerability\n- Violating any applicable laws or breaching any applicable agreements in order to discover vulnerabilities\n- Any form of brute force attacks\n- As we have a known issue of missing HTTPOnly flags on session cookies, any vulnerability that leads to Account Take Over under this basis may be capped at a CVSS Medium\n- We'll accept notifications of domain takeover, but they're not eligible for bounty. **Please note that performing the takeover is strictly prohibited.** \n- XML-RPC Vulnerabilities\n\n# Safe Harbor\nAny activities conducted in a manner consistent with this policy will be considered authorized conduct and we will not initiate legal action against you. If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.\n\nThank you for keeping Trendyol Group and our users safe! \n","has_open_scope":null,"pays_within_one_month":null,"protected_by_gold_standard_safe_harbor":null,"protected_by_ai_safe_harbor":null,"disclosure_declaration":null,"introduction":null,"platform_standards_exclusions":[],"exemplary_standards_exclusions":[],"scope_exclusions":[],"timestamp":"2022-08-16T07:46:50.610Z"}]