bug-bounty-sncf-connect-1

YesWeHackView on YesWeHack
RawAI Enhanced
4
In Scope
15
Out of Scope
In-Scope Assets (4)
Out-of-Scope Assets (15)
AssetCategoryBounty
- hiflow.sncf-connect.comOTHERYes
- office-web-sncf-a.sips-services.comOTHERYes
- ouigo.comOTHERYes
- sncf-voyageurs.comOTHERYes
- ter.sncf.comOTHERYes
- tgvinoui.sncfOTHERYes
- www.garesetconnexions.sncfOTHERYes
- www.groupe-sncf.comOTHERYes
- www.malocationavis.sncf-connect.comOTHERYes
- www.maxjeune-tgvinoui.sncfOTHERYes
- www.sncf-connect-tech.frOTHERYes
- www.sncf-voyageurs.comOTHERYes
- www.sncf.comOTHERYes
The SNCF Connect mobile applications (Android and Apple) are out of scope even if the web services they use are in scope (accessible through paths beginning by 'https://www.sncf-connect.com/bff').OTHERYes
The scope of the Bug Bounty program is defined in the preceding section. To remove any potential ambiguity regarding this scope, the following non‑exhaustive examples illustrate domains that are not included in the program:OTHERYes
Scope Changes (19)
Apr 16, 2026
ChangeAssetCategoryScopeTime
Addedhttps://www.sncf-connect.comURLIn Scope18:33
Addedhttps://sncf-connect.comURLIn Scope18:33
Addedhttps//monidentifiant.sncfURLIn Scope18:33
Addedhttps://www.sncf-connect.com/bffURLIn Scope18:33
Addedthe scope of the bug bounty program is defined in the preceding section. to remove any potential ambiguity regarding this scope, the following non‑exhaustive examples illustrate domains that are not included in the program:OTHEROut of Scope18:33
Added- www.sncf-connect-tech.frOTHEROut of Scope18:33
Added- office-web-sncf-a.sips-services.comOTHEROut of Scope18:33
Added- www.sncf.comOTHEROut of Scope18:33
Added- www.groupe-sncf.comOTHEROut of Scope18:33
Added- www.garesetconnexions.sncfOTHEROut of Scope18:33
Added- sncf-voyageurs.comOTHEROut of Scope18:33
Added- www.sncf-voyageurs.comOTHEROut of Scope18:33
Added- tgvinoui.sncfOTHEROut of Scope18:33
Added- ter.sncf.comOTHEROut of Scope18:33
Added- ouigo.comOTHEROut of Scope18:33
Added- www.maxjeune-tgvinoui.sncfOTHEROut of Scope18:33
Added- www.malocationavis.sncf-connect.comOTHEROut of Scope18:33
Added- hiflow.sncf-connect.comOTHEROut of Scope18:33
Addedthe sncf connect mobile applications (android and apple) are out of scope even if the web services they use are in scope (accessible through paths beginning by 'https://www.sncf-connect.com/bff')OTHEROut of Scope18:33