lucca-bug-bounty-program

YesWeHackView on YesWeHack
RawAI Enhanced
30
In Scope
8
Out of Scope
In-Scope Assets (30)
AssetCategoryBountyQuick Links
/lucca-api/*URLYes-
AbsencesOTHERYes-
Accounting AssistantURLYes-
BenefitsURLYes-
Business Expense (beta)URLYes-
CompensationOTHERYes-
Core HROTHERYes-
EngagementURLYes-
Expenses (not the beta version)URLYes-
InvoicesURLYes-
Lucca (https://apps.apple.com/fr/app/lucca/id1575212411)IOSYes-
Lucca (https://play.google.com/store/apps/details?id=net.ilucca.timmi_pwa.twa)ANDROIDYes-
Lucca - Note de frais (https://apps.apple.com/fr/app/lucca-notes-de-frais/id740679284)IOSYes-
Lucca - Note de frais (https://play.google.com/store/apps/details?id=fr.lucca.cleemy&hl=fr&pli=1)ANDROIDYes-
Lucca AdministrationOTHERYes-
Lucca AnalyticsURLYes-
Lucca Client CenterOTHERYes-
Lucca HomeOTHERYes-
Lucca Shared DocumentsURLYes-
Lucca WhistleblowingURLYes-
OfficeOTHERYes-
Payroll AssistantURLYes-
PayslipOTHERYes-
PerformanceURLYes-
ProjectsURLYes-
RecruitmentURLYes-
Special scenario (see description)OTHERYes-
TimesheetURLYes-
TrainingOTHERYes-
https://security{xxx}.ilucca.net/identity/URLYes-
Out-of-Scope Assets (8)
AssetCategoryBounty
** All API V2 endpoints matching `/api/*` that use the `?fields` parameter are considered out of scope. We're already aware of a common issue affecting these endpoints and are actively working on a global fix. To avoid duplicates, please do not report issues related to these endpoints.OTHERYes
** Cross Establishment issues on Accounting AssistantOTHERYes
** Cross Establishment issues on InvoiceOTHERYes
** Cross Establishment issues on Timesheet.OTHERYes
** Cross Establishments issues on Training.OTHERYes
** HTML Injection without any impact.OTHERYes
** XSS on Cleemy (Note de frais) legacy that require at least an account with manager privilegeOTHERYes
All domains or subdomains not folowing the pattern (security{XXX}) listed in the above list of 'Scopes'.OTHERYes