Rooted
Back to bounty board
MO
Vulnerability disclosure program

Moneybox

moneyboxapp.com / public reporting path

Full+CVD5 signal

One API, four web surfaces and both mobile apps. One gift-code endpoint is known and by design — reporting it earns nothing.

Safe harbor
Good-faith testing inside the published scope is authorised.
Disclosure
First reply typically under a day.
Intake
Policy intake
Scope rules

In scope

  • api.moneyboxapp.com
  • admin.moneyboxapp.org
  • admin-roundups.moneyboxapp.org
  • sycamore.moneyboxapp.org
  • Android app: com.moneyboxapp
  • iOS app: Moneybox

Out of scope

  • Social engineering against staff or customers
  • Physical intrusion or on-site testing
  • Denial of service, load testing or resource exhaustion
  • Credential brute force or password spraying
  • Unthrottled automated scanning
  • Accessing data belonging to real users
  • scope.UNLISTED_SUBDOMAINS
Scope rules

What Rooted expects in a valid report

In scope

Owned public web assets, auth/session logic, exposed APIs, account boundaries, sensitive data exposure and clear misconfiguration with reproducible impact.

Out of scope

Social engineering, physical testing, spam, denial of service, brute force, persistence, malware, extortion language and access to data that is not yours.

Report quality

Include affected asset, severity, exact steps, observed impact and safe evidence. We score reports faster when the reproduction is clean.

Verification

Rooted reviews the submission and may coordinate with the listed program. Points are released only after the finding is confirmed.