April bounty stats
For those that haven't read the crap that I write before, I have tended to only log reports that are high-impact and above. The reasoning behind that is that I can't be arsed to create a PoC, write up a report, and argue the toss with triage for $100. But even so, something like 80% of my reports leave me feeling messed around anyway, mostly through being descoped or randomly downgraded.
I had a theory that the high-impact reports were getting messed around disproportionally in comparison to the low-impact reports, so for April I decided to log everything I found.
Some are still in triage (platform or programme), but the results so far are:
3x high-impact
- 1x accepted but downgraded (stored XSS downgraded to medium)
- 1x descoped by programme ("no longer accepting submissions for this host")
- 1x rejected by platform (triage error: commented, and will resubmit if no response)
6x medium-impact
- 1x accepted and already paid out as per scope
- 3x still in triage
- 1x descoped by programme ("no longer accepting this type of bug")
- 1x rejected by platform (triage error: commented, and will resubmit if no response)
It's a limited set of data, and the final outcome has yet to be decided for the majority, but the general feel is that pretty much all the reports get messed around just the same ;)