
Found a security issue? Please report it responsibly. We appreciate your help in keeping Chargezen secure.
Expected Response Time
24 hours
Critical issues: same business day
Rewards are determined based on severity, impact, and quality of the report.
Remote code execution, SQL injection, authentication bypass, data breach
$5,000 - $15,000
Examples:
Significant data exposure, privilege escalation, stored XSS with impact
$1,000 - $5,000
Examples:
Limited data exposure, CSRF, reflected XSS, information disclosure
$250 - $1,000
Examples:
Minor issues, best practice violations, low-impact information disclosure
$50 - $250
Examples:
High-quality reports help us fix issues faster and may result in higher rewards.
Vulnerability Type
Classification (XSS, SQLi, IDOR, etc.)
Affected URL/Endpoint
Specific location of the vulnerability
Steps to Reproduce
Clear, numbered steps anyone can follow
Proof of Concept
Screenshots, videos, or code demonstrating the issue
Impact Assessment
Potential impact if exploited by an attacker
Suggested Fix
Optional, but appreciated recommendations
When conducting security research according to this policy, we consider this research to be:
Help us keep Chargezen secure. Submit your vulnerability report and join our security hall of fame.
