hellofresh/hellofresh

IntigritiView on Intigriti
RawAI Enhanced
42
In Scope
1
Out of Scope
In-Scope Assets (42)
AssetCategoryBountyQuick Links
*.bcrc.ioWILDCARDYes
*.becoolcouriers.com.auWILDCARDYes
*.becoolrefrigeratedcouriers.com.auWILDCARDYes
*.chefsplate.comWILDCARDYes
*.everyplate.comWILDCARDYes
*.everyplate.com.auWILDCARDYes
*.factor75.comWILDCARDYes
*.goodchop.comWILDCARDYes
*.greenchef.co.ukWILDCARDYes
*.greenchef.comWILDCARDYes
*.helloconnect.orgWILDCARDYes
*.hellofresh.<tld>WILDCARDYes
*.youfoodz.comWILDCARDYes
1015997735IOSYes-
1265572034IOSYes-
1471311837IOSYes-
1536589530IOSYes-
1545961260IOSYes-
970107419IOSYes-
Broken authentication or access control leading to PII exposureOTHERYes-
Database query injection in applications that store customer dataOTHERYes-
IDOR or any logical flaw that cause PII exposureOTHERYes-
Leaked secrets of critical systems (Bitrise, Github, AWS, etc.)OTHERYes-
RCE in applications hosted on HelloFresh AWSOTHERYes-
SSRF resulting in exposure of critical secrets (AWS API keys etc.)OTHERYes-
Weak or leaked corporate credentials leading to PII exposureOTHERYes-
com.chefsplate.ChefsPlateANDROIDYes
com.everyplate.androidANDROIDYes
com.factor75.factor75ANDROIDYes
com.greenchef.GreenChefANDROIDYes
com.hellofresh.androidappANDROIDYes
com.youfoodz.appANDROIDYes
https://api.becoolcouriers.com.au/URLYes
https://factorform.com/URLYes
https://greenchef.com/ URLYes
https://portalv2.becoolcouriers.com.au/ URLYes
https://www.chefsplate.com/ URLYes
https://www.everyplate.com/ URLYes
https://www.factor75.com/ URLYes
https://www.goodchop.com/ URLYes
https://www.hellofresh.com/ URLYes
https://youfoodz.com/ URLYes
Out-of-Scope Assets (1)
AssetCategoryBounty
blog.*.tldWILDCARDYes