Introduction
We invite you to explore our Vulnerability Disclosure Program and contribute to the ongoing security of Kaufland Marketplace. If you’re a security researcher with a passion for ethical hacking, your expertise can make a real difference in safeguarding our platform and our customers. Let's work together to create a safer digital marketplace for all. Note that if your finding is within scope and severe enough, we may decide to reward and invite you to our private program.
Our worst-case scenarios are:
Data exfiltration - Any vulnerability that allows attackers to access, exfiltrate, or expose sensitive information such as Personally Identifiable Information (PII) related to customers and sellers. This includes unauthorized access to data storage, APIs, or any data processing pipelines.
Payment process - Vulnerabilities that enable attackers to manipulate payment processes, such as altering the price of items, bypassing payment gateways, or creating fraudulent transactions. This includes any flaws in the checkout process, payment integrations, or order management systems.
Injection attacks - Vulnerabilities that allow attackers to perform injection attacks, such as SQL injection, command injection, or file upload attacks, which can lead to unauthorized access to databases, backend systems, or operating systems. This includes any injection vulnerabilities in web applications, APIs, or backend services.
Remote code execution - Any vulnerability that allows an attacker to execute arbitrary code on your servers or within your infrastructure. This includes vulnerabilities in software, misconfigured services, or insecure scripting that can be exploited remotely.
Cloud misconfiguration - Misconfigurations in cloud services or infrastructure that can lead to unauthorized access, data leaks, or compromise of cloud resources. This includes issues like publicly accessible storage buckets, insecure API endpoints, or misconfigured access controls.
Feedback
Would you like to help us improve our program or have some feedback to share, please send your anonymous feedback here:
Program feedback link
Please note this form will be checked periodically and should not be used for submission or support queries.