cetelem-fr
7
In Scope
10
Out of Scope
In-Scope Assets (7)
| Asset | Category | Bounty | Quick Links | |
|---|---|---|---|---|
| https://api-secure.bnpparibas-pf.com | URL | Yes | ||
| https://api.bnpparibas-pf.com | URL | Yes | ||
| https://apps.apple.com/fr/app/cetelem/id569861019 | IOS | Yes | - | |
| https://play.google.com/store/apps/details?id=fr.cetelem.android&hl=fr | ANDROID | Yes | ||
| https://souscription.cetelem.fr/* | URL | Yes | ||
| https://www.cetelem.fr/* | URL | Yes | ||
| https://www.cetelem.fr/fr/partenaire/1001989870 | URL | Yes |
Out-of-Scope Assets (10)
| Asset | Category | Bounty | |
|---|---|---|---|
| - https://www.cetelem.fr/fr/virement-express | OTHER | Yes | |
| Any (sub-)domain or path that is not explicitely listed in the ‘Scope’ section are not part of the scope. | OTHER | Yes | |
| Endpoints from https://api.bnpparibas-pf.com and https://api-secure.bnpparibas-pf.com that are not directly requested from Cetelem mobile app. | OTHER | Yes | |
| https://api-nav-psd2.bddf.bnpparibas/as/psd2/retail/authorize | OTHER | Yes | |
| https://api.bnpparibas-pf.com/fr/monext_issuing/v1 | OTHER | Yes | |
| https://api.fabrick.com/api/fabrick/third-parties/mastercard/idcm/bnpp/v1.0 | OTHER | Yes | |
| https://api.mypurecloud.de | OTHER | Yes | |
| https://digital-cloud.apis.medallia.eu | OTHER | Yes | |
| https://login.mypurecloud.de | OTHER | Yes | |
| https://resources.digital-cloud.medallia.eu | OTHER | Yes |
Scope Changes (17)
Apr 16, 2026
| Change | Asset | Category | Scope | Time |
|---|---|---|---|---|
| Added | https://www.cetelem.fr/* | URL | In Scope | 18:33 |
| Added | https://souscription.cetelem.fr/* | URL | In Scope | 18:33 |
| Added | https://play.google.com/store/apps/details?id=fr.cetelem.android&hl=fr | ANDROID | In Scope | 18:33 |
| Added | https://apps.apple.com/fr/app/cetelem/id569861019 | IOS | In Scope | 18:33 |
| Added | https://api.bnpparibas-pf.com | URL | In Scope | 18:33 |
| Added | https://api-secure.bnpparibas-pf.com | URL | In Scope | 18:33 |
| Added | https://www.cetelem.fr/fr/partenaire/1001989870 | URL | In Scope | 18:33 |
| Added | - https://www.cetelem.fr/fr/virement-express | OTHER | Out of Scope | 18:33 |
| Added | any (sub-)domain or path that is not explicitely listed in the ‘scope’ section are not part of the scope | OTHER | Out of Scope | 18:33 |
| Added | https://login.mypurecloud.de | OTHER | Out of Scope | 18:33 |
| Added | https://api.mypurecloud.de | OTHER | Out of Scope | 18:33 |
| Added | https://api-nav-psd2.bddf.bnpparibas/as/psd2/retail/authorize | OTHER | Out of Scope | 18:33 |
| Added | https://resources.digital-cloud.medallia.eu | OTHER | Out of Scope | 18:33 |
| Added | https://digital-cloud.apis.medallia.eu | OTHER | Out of Scope | 18:33 |
| Added | https://api.fabrick.com/api/fabrick/third-parties/mastercard/idcm/bnpp/v1.0 | OTHER | Out of Scope | 18:33 |
| Added | https://api.bnpparibas-pf.com/fr/monext_issuing/v1 | OTHER | Out of Scope | 18:33 |
| Added | endpoints from https://api.bnpparibas-pf.com and https://api-secure.bnpparibas-pf.com that are not directly requested from cetelem mobile app | OTHER | Out of Scope | 18:33 |