makemytrip-pvt-ltd-bug-bounty-program

YesWeHackView on YesWeHack
RawAI Enhanced
3
In Scope
7
Out of Scope
In-Scope Assets (3)
AssetCategoryBountyQuick Links
*.makemytrip.comURLYes
https://apps.apple.com/us/app/makemytrip-flight-hotel-bus/id530488359IOSYes-
https://play.google.com/store/apps/details?id=com.makemytrip&hl=enANDROIDYes
Out-of-Scope Assets (7)
AssetCategoryBounty
All domains or subdomains not listed in-scope.OTHERYes
Complete Connect Application formerly known as IngoOTHERYes
Reporting issues on such endpoints where dependency-check & TTL is present will not be considered as a valid bug, however if bug hunter identify any such endpoint lacking dependency-check & TTL would be considered as IDOR.OTHERYes
There are certain endpoints where replaying booking IDs can retrieve other customer details, however for every such endpoints there is a dependency-check between 2 or more IDs is implemented.OTHERYes
homestayawards.makemytrip.comOTHERYes
ilearn.makemytrip.comOTHERYes
planner.makemytrip.comOTHERYes