My Appointments
My Bookings
My Orders
Security @ Cars24
CARS24 is a next-generation eCommerce platform for pre-owned cars. We provide the best in class experience for car buyers by offering a wide assortment of certified cars that are home delivered with a click of a button while sellers get the best price of their vehicles in less than 1 hour.
Cars24 is committed to working with security experts across the globe to stay up to date with the latest security techniques & vulnerabilities, Feel free to inspect applications. If you have discovered a security issue that you believe we should know about, we’d welcome working with you. Please let us know about it and we'll make every effort to quickly correct the issue.
Check out the list of researchers that were provided with the Hall of Fame
Upon receipt of the finding, we will conduct an internal investigation to understand the full impact of the vulnerability. We then assess the severity based on CARS24 Business Impacts because of the vulnerability.
Note that cars24 allows self-registration, -- which makes vulnerabilities exploitable without authentication a lot more impactful. For this reason, any vulnerability that requires a user account will not be considered critical.
Also, any high/critical vulnerabilities that require a MITM, will be considered with Low/medium as the communication is encrypted with the latest TLS versions.
Actions/areas that are explicitly NOT considered to be in-scope:
Vulnerabilities with the following severities
Critical | Hall of Fame & Letter of Recommendation |
High | Hall of Fame & Letter of Recommendation |
Medium | Hall of Fame |
CARS24 will make the best effort to meet the following SLAs for hackers participating in our program:
You are responsible for complying with any applicable laws. You are not eligible to participate in this program if you are currently an employee of Cars24 or any of its subsidiaries.
Reports from former employees, the immediate family of current employees, or other associates of Cars24 that may present a conflict of interest in the program's goals will be more thoroughly reviewed. They may not qualify for the stated bounty awards at Cars24's discretion.
Upon submission of your finding, you are agreeing with the terms & conditions and are liable to the NDA
You can reach out to us at [email protected]
Happy Hacking :)