OUT OF SCOPE

  • Security Best Practices, i.e., Security Headers
  • Social Engineering, Phishing
  • Physical Attacks
  • Missing Cookie Flags
  • CSRF with minimal impact, i.e., Login CSRF, Logout CSRF
  • Content Spoofing
  • Stack Traces, Path Disclosure, Directory Listings
  • SSL/TLS best practices
  • Banner Grabbing
  • CSV Injection
  • Reflected File Download
  • Reports on Out of dated browsers
  • DOS/DDOS (including no Rate Limits and file size restrictions)
  • Host header Injection without a demonstrable impact
  • Scanner Outputs
  • Vulnerabilities on Third Party Products
  • User Enumeration
  • Password Complexity
  • HTTP Trace Method
  • Issues found in third party software used by Xsolla
  • Clickjacking
  • Self XSS
  • Email Spoofing - SPF Records Misconfiguration
  • Open redirect with host header injection
  • Private IP addresses disclosure

Reports on:

  • A payment being declined or not going through.
  • A refund that hasn’t been approved, or funds haven’t reached your account yet.
  • The payment system you’d like to use is temporarily unavailable or not available for your region/mobile carrier.
  • You have not received the purchase or the bonus associated with it.
  • Issues related to scheduled or unscheduled downtimes, connection issues, etc.
  • Flaws found on our profiles on Facebook, Twitter, LinkedIn, Reddit, etc. and our partners’ websites.

For these and other payment-related issues, please contact our 24/7 Customer Service team at help.xsolla.com.

CONTACT US
REPORT SUBMISSION

By submitting a bug report, you agree to comply with the Xsolla Bounty Program Policy, which prohibits both public and private disclosure of any vulnerability or bug details related to Xsolla.

By participating in this program, you agree to adhere to the above rules and conditions. All rules must be followed to be eligible for rewards.

To protect the security of submitted reports, all vulnerability details, including Proof-of-Concept (PoC) scripts, videos, screenshots, and any other supporting materials, may only be shared with us through our submission form (ticketing system). We do not accept materials delivered via external links or hosting of any kind, including third-party providers, CDNs, cloud-storage or file-sharing services (such as YouTube, Google Drive, Streamlabs), or self-hosted websites.

Providing materials by any of these means this may be considered a violation of the Program’s Rules. Please upload videos\screenshots\pictures directly through the submission form. At this time, POC files must NOT exceed 25MB in size and 7 minutes in duration. You are welcome to shorten or compress the files as needed to meet these requirements.

Please make sure to use this User-Agent string for testing:xsolla-bugbounty-%your-email-before@%Learn more...
Average response time : 48 hours for tickets