cetelem-fr

YesWeHackView on YesWeHack
RawAI Enhanced
7
In Scope
10
Out of Scope
In-Scope Assets (7)
Out-of-Scope Assets (10)
AssetCategoryBounty
- https://www.cetelem.fr/fr/virement-expressOTHERYes
Any (sub-)domain or path that is not explicitely listed in the ‘Scope’ section are not part of the scope.OTHERYes
Endpoints from https://api.bnpparibas-pf.com and https://api-secure.bnpparibas-pf.com that are not directly requested from Cetelem mobile app.OTHERYes
https://api-nav-psd2.bddf.bnpparibas/as/psd2/retail/authorizeOTHERYes
https://api.bnpparibas-pf.com/fr/monext_issuing/v1OTHERYes
https://api.fabrick.com/api/fabrick/third-parties/mastercard/idcm/bnpp/v1.0OTHERYes
https://api.mypurecloud.deOTHERYes
https://digital-cloud.apis.medallia.euOTHERYes
https://login.mypurecloud.deOTHERYes
https://resources.digital-cloud.medallia.euOTHERYes
Scope Changes (17)
Apr 16, 2026
ChangeAssetCategoryScopeTime
Addedhttps://www.cetelem.fr/*URLIn Scope18:33
Addedhttps://souscription.cetelem.fr/*URLIn Scope18:33
Addedhttps://play.google.com/store/apps/details?id=fr.cetelem.android&hl=frANDROIDIn Scope18:33
Addedhttps://apps.apple.com/fr/app/cetelem/id569861019IOSIn Scope18:33
Addedhttps://api.bnpparibas-pf.comURLIn Scope18:33
Addedhttps://api-secure.bnpparibas-pf.comURLIn Scope18:33
Addedhttps://www.cetelem.fr/fr/partenaire/1001989870URLIn Scope18:33
Added- https://www.cetelem.fr/fr/virement-expressOTHEROut of Scope18:33
Addedany (sub-)domain or path that is not explicitely listed in the ‘scope’ section are not part of the scopeOTHEROut of Scope18:33
Addedhttps://login.mypurecloud.deOTHEROut of Scope18:33
Addedhttps://api.mypurecloud.deOTHEROut of Scope18:33
Addedhttps://api-nav-psd2.bddf.bnpparibas/as/psd2/retail/authorizeOTHEROut of Scope18:33
Addedhttps://resources.digital-cloud.medallia.euOTHEROut of Scope18:33
Addedhttps://digital-cloud.apis.medallia.euOTHEROut of Scope18:33
Addedhttps://api.fabrick.com/api/fabrick/third-parties/mastercard/idcm/bnpp/v1.0OTHEROut of Scope18:33
Addedhttps://api.bnpparibas-pf.com/fr/monext_issuing/v1OTHEROut of Scope18:33
Addedendpoints from https://api.bnpparibas-pf.com and https://api-secure.bnpparibas-pf.com that are not directly requested from cetelem mobile appOTHEROut of Scope18:33