Bug Bounty Hunting
Program Types
Type
Description
Finding Programs
Program Structure Checklist
Element
Check
Bug Report Structure
Section
Content
CVSS 3.1 Calculator
Attack Vector (AV)
Value
Meaning
Attack Complexity (AC)
Value
Meaning
Privileges Required (PR)
Value
Meaning
User Interaction (UI)
Value
Meaning
Scope (S)
Value
Meaning
CIA Impact
Value
C/I/A Impact
CVSS Score Examples
Critical (9.8) - RCE Unauth
High (8.8) - SQLi Auth Required
Medium (5.4) - CSRF
Medium (5.5) - Stored XSS (Admin Panel)
Low (3.5) - Reflected XSS
Common CWEs
CWE
Vulnerability
Report Title Examples
Good Report Examples (HackerOne)
Communication Rules
Do
Don't
Disagreement Process
Quick POC Templates
XSS POC
SQLi POC
CSRF POC
SSRF POC
Last updated