Welcome to the Posti bug bounty programme! Posti is one of the leading delivery and fulfillment companies in Finland, Sweden and the Baltic countries, that offers a wide range of postal, logistics, freight and eCommerce services. Thank you for your interest in helping us protect our products, services and users. We appreciate the time, effort and competence that you offer to make our company more secure. Thank you in advance for your valuable contributions. Before reporting, please read very carefully the scope of the programme, the rules of engagement and the out of scope section. When reporting, please provide well structured submissions with clear and logical reproduction steps, the affected endpoints and the minimal evidence needed to demonstrate the impact of the issue. The clearer and more understandable a report is, the sooner we will get back to you. Please do not mention any theoretical, hypothetical scenarios but only concretely exploitable cases. We will do our best, considering our teams workload, schedules and availability, to promptly acknowledge the submissions, investigate the issues and keep you informed.
By participating in this program, you agree to:
- Respect the Community Code of Conduct
- Respect the Intigriti Terms and Conditions
- Respect the scope of the program
- Not to discuss or disclose vulnerability information with any third parties in any form and at any time
Important
When testing webshops where it's possible to order and/or buy Posti products and services (such as stamps, parcels, etc.) it can be tested for example if it's possible to buy them without actually paying for them but it's not allowed to proceed to a legitimate purchase. Posti will not refund any possible costs that the security researchers might incur when trying to purchase any products and services.
No systems should be intentionally disrupted. The security researchers can demonstrate that by taking some steps, a system might potentially be disrupted but they should not continue to the actual step that would bring down the system.
Introduction
We have done our best to build secure systems and now we would like to ask for your help to spot something that we might have missed.
The focus areas of the programme are outlined in the assets list. As follows a few examples of cases where we are particularly interested:
- An attacker manages to modify data in Posti systems
- An attacker gains access to our customers personal data
- An attacker manages to bring down our systems making them inaccessible
- Ransomware attacks
Test accounts and credentials
No accounts and credentials will be provided by Posti. If they want, the researchers with Finnish bank credentials or IDs, can create their own real account in those systems which allow it (please notice, only real account data must be provided). If you cannot create an account by yourself, that's ok.
Feedback
Would you like to help us improve our program or have some feedback to share (for example, would you like to suggest adding to the program an API or a domain related to those already in the scope)? Then please send your anonymous feedback here:
Program feedback link
Please note this form will be checked periodically and should not be used for submission or support queries.
Known Issues (last updated: 26 May 2026)
POSTI-M2R4VUYA - [shop.posti.fi] - Business Logic: VAT calculation
Do not report any issues regarding the VAT calculation.
Application
- API key disclosure without proven business impact
- Wordpress usernames disclosure
- Pre-Auth Account takeover/OAuth squatting
- Self-XSS that can't be used to exploit other users
- Verbose messages/files/directory listings without disclosing any sensitive information
- Information disclosure of non-sensitive data (version disclosure, banner grabbing or other banner identification issues, descriptive error messages or headers, stack traces, application or server errors) without a direct and demonstrated exploit
- CORS misconfiguration on non-sensitive endpoints
- Missing cookie flags
- Missing security headers
- Cross-site Request Forgery with no or low impact
- Presence of autocomplete attribute on web forms
- Reverse tabnabbing
- Bypassing rate-limits or the non-existence of rate-limits
- Missing security best practices or best practices violations that do not pose a direct security risk or a demonstrated exploit
- Clickjacking without proven impact/unrealistic user interaction
- CSV Injection
- Sessions not being invalidated (logout, enabling 2FA, etc.)
- Tokens leaked to third parties
- Anything related to email spoofing, SPF, DMARC or DKIM
- Weak SSL/TLS ciphers without a demonstrable exploit
- Content injection without being able to modify the HTML
- Username/email enumeration
- Employee emails disclosure
- Email bombing
- HTTP Request smuggling without any proven impact
- Homograph attacks
- XMLRPC enabled
- Not stripping metadata of files
- Same-site scripting
- Subdomain takeover without taking over the subdomain
- Arbitrary file upload without proof of the existence of the uploaded file
- Blind SSRF without proven business impact (pingbacks aren't sufficient)
- Disclosed/misconfigured Google Maps API keys
- Host header injection without proven business impact
General
- In case that a reported vulnerability was already known to the company from their own tests, it will be flagged as a duplicate
- Theoretical security issues with no realistic exploit scenario(s) or attack surfaces, or issues that would require complex end user interactions to be exploited
- Spam, social engineering and physical intrusion
- DoS/DDoS attacks or brute force attacks
- Vulnerabilities that only work on software that no longer receive security updates
- Attacks requiring physical access to a victim's computer/device, man in the middle or compromised user accounts
- Recently discovered zero-day vulnerabilities found in in-scope assets within 14 days after the public release of a patch or mitigation may be reported, but are usually not eligible for a bounty
- Reports that state that software is out of date/vulnerable without a proof-of-concept
Mobile
- Shared links leaked through the system clipboard
- Any URIs leaked because a malicious app has permission to view URIs opened
- The absence of certificate pinning
- Sensitive data in URLs/request bodies when protected by TLS
- Lack of obfuscation
- Path disclosure in the binary
- Lack of jailbreak & root detection
- Crashes due to malformed URL Schemes
- Lack of binary protection (anti-debugging) controls, mobile SSL pinning
- Snapshot/Pasteboard leakage
- Runtime hacking exploits (exploits only possible in a jailbroken environment)
- API key leakage used for insensitive activities/actions
This program follows Intigriti's triage standards
Where can we get credentials for the app?
We don’t provide any credentials to test user roles. However, if the application offers a self-register functionality, you can create your personal account. If you decide to do so, please use your @intigriti.me address and keep in mind that the domains in the scope of the program are mostly production environments, therefore your account / profile should not include fake data.
For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.
It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.






























