There are 7 regions of Watsons online retail platforms. They share the same source code, we only accept one report for one issue across the following domains. If you are testing functionalities that require you to be authenticated, please ensure you register with your @wearehackerone.com email address.
In Scope
=========
>https://www.watsons.com.my
>https://www.watsons.com.ph
>https://www.watsons.co.th
>https://www.watsons.com.tw
>https://www.watsons.com.hk
>https://www.watsons.co.id
>https://www.watsons.com.sg
>https://www10.watsons.com.my
>https://www10.watsons.com.ph
>https://www10.watsons.co.th
>https://www20.watsons.co.th
>https://www10.watsons.com.tw
>https://www10.watsons.com.hk
>https://www10.watsons.co.id
>https://www10.watsons.com.sg
>api.watsons.com.my
>api.watsons.com.ph
>api.watsons.com.th
>api.watsons.com.tw
>api.watsons.com.hk
>api.watsons.co.id
>api.watsons.com.sg
>Mobile app retail (Android and iOS)
*Not eligible for bounty*
> \*.watsons.co.th
>\*.watsons.co.id
>\*.watsons.com.sg
This asset is specifically for Watsons TW subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.watsons.com.tw/
This is the API server for the www.iciparisxl.lu website
This is the API server of the Drogas mobile app in Lithuania
This is the API server for the www.iciparisxl.be website
This is the API server for the www.watsons.com.my website
This asset is specifically for Watsons Singapore subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In Scope
=========
>*.watsons.com.sg
This is the API server for the superdrug.com website
This asset is specifically for Marionnaud CH subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.marionnaud.ch/
This asset is specifically for Watsons SG subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.watsons.com.sg/
This asset is specifically for Savers subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.savers.co.uk/
This is our Superdrug Mobile (Android) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App link: https://play.google.com/store/apps/details?id=superdrug.com.beautycard&hl=en
This is our online Austrian perfumery. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This subdomain is used to store static content for the www.drogas.lv e-commerce website
This hostname is used for the Watsons Turkey mobile app
This asset is specifically for PNS subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.parknshop.com/
This is our Marionnaud (iOS) app in France. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/fr/app/marionnaud-beaut%C3%A9-soins/id1127368763
This is the API server for the Watsons Taiwan Mobile App
This is our online Hungarian perfumery. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This is our Watsons HongKong Mobile (Android) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=com.ndn.android.watsons
This is our PNS Mobile (Android) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=com.parknshop.parknshopapp
This subdomain is used to store static content for the www.marionnaud.ch e-commerce website.
This asset is specifically for Watsons TW's subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In Scope
=========
>*.watsons.com.tw/
This is our Dutch online retail platform. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This website is similar to other websites (Such as Superdrug). Please keep in mind that issues might be considered duplicates if it is reported on another website already.
This asset is specifically for Moneyback's subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In Scope
=========
> *.moneyback.com.hk/
This asset is our Benelux perfume retail website. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
In scope
=====================
>https://www.iciparisxl.nl/
>https://www.iciparisxl.be/
>https://www.iciparisxl.lu/
>https://app.iciparisxl.nl/
>https://app.iciparisxl.be/
>https://app.iciparisxl.lu/
>Mobile app retail (Android and iOS)
*Not eligible for bounty*
>https://www.iciparisxl.nl/blog
>https://www.iciparisxl.be/blog
>https://www.iciparisxl.lu/blog
This asset is specifically for Watsons TH subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.watsons.co.th/
This is our Marionnaud (iOS) app in Italy. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/it/app/marionnaud/id883671274
This asset is specifically for Watsons TR subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.watsons.com.tr/
This is our ICI Paris XL (Android) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App link:
https://play.google.com/store/apps/details?id=com.iciparisxl.app
This asset is specifically for Superdrug subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.superdrug.com/
This asset is specifically for Watsons VN subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.watsons.vn/
This asset is specifically for Watsons PH subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.watsons.com.ph/
This asset is specifically for Fortress's subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In Scope
=========
> *.fortress.com.hk/
This asset is specifically for Watsons TH's subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In Scope
=========
>*.watsons.co.th
Bounty table header
This asset is specifically for Watsons Philippines subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In Scope
=========
>*.watsons.com.ph/
This asset is specifically for PARKnSHOP's subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In Scope
=========
> *.parknshop.com/
This is our Dutch online Perfumery. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This website is similar to other websites (Such as Superdrug and Kruidvat). Please keep in mind that issues might be considered duplicates if it is reported on another website already.
This is our Drogas (iOS) app in Latvia. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/lv/app/drogas/id1564705644
This is our online Italian perfumery. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This is our Watsons TaiWan Mobile (Android) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=tw.com.watsons.app
This is our Marionnaud (Android) app in France. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=com.marionnaud.marionnaudfrance
This asset is specifically for Watsons HK's subdomain assets.
Please note that for subdomains (tier 3), will only pay out reports that have a high or critical severity.
In Scope
=========
>*.watsons.com.hk/
This subdomain is used to store static content for the www.fortress.com.hk e-commerce website.
This is our online retail platform for health and beauty products in the Philippines.
If you are testing a functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This is our Marionnaud (Android) app in Italy. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=it.marionnaud.customer
This subdomain is used to store static content for the www.drogas.lt e-commerce website
This is our MoneyBack Mobile (Android) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=com.asw.moneyback
This subdomain is used to store static content for the www.iciparisxl.be e-commerce website
This asset is specifically for Marionnaud HU subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.marionnaud.hu/
This asset is specifically for Marionnaud SK subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.marionnaud.sk/
This is our ICI Paris XL (iOS) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App link:
https://apps.apple.com/nl/app/ici-paris-xl-beauty/id1061895392
This is our The Perfume Shop (Android) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=com.theperfumeshop.customer
This asset is specifically for Moneyback subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.moneyback.com.hk/
This is our Belgium online Perfumery. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This website is similar to other websites (Such as Superdrug and Kruidvat). Please keep in mind that issues might be considered duplicates if it is reported on another website already.
This is our Latvian online retail platform. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
The Perfume Shop is one of our leading e-commerce perfumery websites. If you are testing functionalities that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
In scope
=====================
>https://www.theperfumeshop.com/
>https://apptps.theperfumeshop.com/
>ThePerfumeShop.App.IOS
>ThePerfumeShop.App.Android
*Not eligible for bounty*
>https://www.theperfumeshop.com/blog
>https://www.theperfumeshop.com/ie/blog
>https://apptps.theperfumeshop.com/blog
>https://apptps.theperfumeshop.com/ie/blog
>*.theperfumeshop.com (See separate subdomain asset)
MoneyBack has turned shopping into fantastic rewards for families across Hong Kong. If you are testing a functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This is the API server for the Superdrug mobile app
This asset is specifically for Marionnaud AT subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.marionnaud.at/
This asset is specifically for Marionnaud RO subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.marionnaud.ro/
This is our online retail platform for health and beauty products in Hong Kong.
If you are testing a functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This is the API server for the www.theperfumeshop.com website
This asset is specifically for Kruidvat's subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In scope
=====================
>\*.kruidvat.nl/
>\*.kruidvat.be/
This is our Marionnaud (iOS) app in Romania. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/ro/app/marionnaud-romania/id1021924260
This is our Marionnaud (iOS) app in Switzerland. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/ch/app/id1486316902
This asset is specifically for ICI Paris XL NL subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.iciparisxl.nl/
This is our API Server for our Fortress website (www.fortress.com.hk)
This asset is specifically for Trekpleister's subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In scope
=====================
>\*.trekpleister.nl
This is our Lithuanian online retail platform. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This asset is specifically for Marionnaud CZ subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.marionnaud.cz/
This asset is specifically for Trekpleister subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.trekpleister.nl/
This asset is specifically for Watsons HK subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.watsons.com.hk/
This asset is specifically for Watsons ID subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.watsons.co.id/
This subdomain is used to store static content for the www.watsons.co.id e-commerce website.
This is our Drogas (Android) app in Latvia. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=lv.drogas.consumer
This is the API server of the Marionnaud mobile app in France
This is our Belgium online Perfumery. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This website is similar to other websites (Such as Superdrug and Kruidvat). Please keep in mind that issues might be considered duplicates if it is reported on another website already.
This asset is specifically for Watsons MY subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.watsons.com.my/
This asset is specifically for The Perfume Shop subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.theperfumeshop.com/
This asset is specifically for Watsons Malaysia subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In Scope
=========
>*.watsons.com.my/
MoneyBack has turned shopping into fantastic rewards for families across Hong Kong. If you are testing a functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
In Scope
=========
>www.moneyback.com.hk
>Mobile app retail (Android and iOS)
ParknShop is our leading e-commerce website for every day items in Hong Kong. If you are testing functionalities that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
In Scope
=========
>https://www.parknshop.com
>https://www10.parknshop.com
>api.parknshop.com
>Mobile app retail (Android and iOS)
This is our Watsons Philippines Mobile (IOS) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/hk/app/watsons-philippines/id1438203234
This is our Watsons (Android) app in Turkey. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=com.mobular.watsons
Fortress is one of our leading e-commerce websites in Hong Kong and Macau.
Customers could shop for electrical appliances after paying their electricity bills. If you are testing functionalities that require you to be authenticated,
please ensure you register with your @wearehackerone.com email address.
In Scope
=========
>https://www.fortress.com.hk
>Mobile app retail (Android and iOS)
This subdomain is used to store static content for the www.marionnaud.at e-commerce website.
This is our Benelux online retail platform for health and beauty products. If you are testing a functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
In scope
=====================
>https://www.kruidvat.nl/
>https://www.kruidvat.be/
>https://app.kruidvat.nl/
>https://app.kruidvat.be/
>Mobile app retail (Android and iOS)
*Not eligible for bounty*
>https://www.kruidvat.nl/persoonlijk/
>https://www.kruidvat.nl/blog/
>https://www.kruidvat.be/blog/
This is our online retail platform for health and beauty products in Malaysia.
If you are testing a functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This is our MoneyBack Mobile (Android) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/hk/app/fortress/id1133110850
This is our Watsons Singapore Mobile (IOS) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/hk/app/watsons-sg-the-official-app/id449412168
This is our Watsons Philippines Mobile (IOS) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/hk/app/watsons-philippines/id1438203234
This is our Watsons TaiWan Mobile (IOS) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/hk/app/%E5%B1%88%E8%87%A3%E6%B0%8F%E5%8F%B0%E7%81%A3/id477968775
This is our Watsons Thailand Mobile (IOS) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/hk/app/watsons-th/id619935224
This is our online retail platform for health and beauty products in Indonesia.
If you are testing a functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This subdomain is used to store static content for the www.watsons.co.th e-commerce website.
This is our Dutch online retail mobile app for Belgium customers. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This app is similar to other apps (Such as Superdrug). Please keep in mind that issues might be considered duplicates if it is reported on another website already.
App Link
https://play.google.com/store/apps/details?id=be.kruidvat.voordeelkaart
The Perfume Shop (subdomains)
This asset is specifically for The Perfume Shop's subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In scope
=====================
>\*.theperfumeshop.com/
This is the API server of the Kruidvat Mobile App in Belgium
This is our Marionnaud (Android) app in Austria. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=at.marionnaud.customer
This asset is specifically for Drogas LT subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.drogas.lt/
This asset is specifically for Fortress HK subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.fortress.com.hk/
This asset is specifically for ICI Paris XL BE subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.iciparisxl.be/
This is the API server for the Watsons Indonesia Mobile App
This is the wordpress blog for Watsons Turkey. This asset is regarded as (Tier 3) subdomain.
This is our Watsons Indonesia Mobile (Android) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=com.watsons.id.android
This is the API server for the www.marionnaud.at e-commerce website.
The Perfume Shop is one of our leading e-commerce perfumery websites. If you are testing functionalities that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This asset is specifically for Marionnauds' subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In scope
=====================
>\*.marionnaud.it
>\*.marionnaud.fr
>\*.marionnaud.ch
>\*.marionnaud.ro
>\*.marionnaud.hu
>\*.marionnaud.sk
>\*.marionnaud.cz
This is our Superdrug Mobile (IOS) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App link: https://apps.apple.com/gb/app/superdrug/id1267896687
This is the API server for the Watsons Hong Kong Mobile App
Superdrug is one of our leading e-commerce websites in health and beauty. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
In scope
=====================
>https://www.superdrug.com/
>https://app.superdrug.com/
>Superdrug.App.IOS
>Superdrug.App.Android
*Not eligible for bounty*
>https://www.superdrug.com/blog
This is the API server for the www.marionnaud.ch e-commerce website.
This subdomain is used to store static content for the www.marionnaud.fr e-commerce website.
This is the API server of the ICI Paris XL mobile app in Luxembourg
This asset is specifically for Kruidvat NL subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.kruidvat.be/
This asset is specifically for PNS's subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In Scope
=========
> \*.pns.hk/
Fortress is one of our leading e-commerce websites in Hong Kong and Macau.
Customers could shop for electrical appliances after paying their electricity bills. If you are testing functionalities that require you to be authenticated,
please ensure you register with your @wearehackerone.com email address.
This is our Watsons TaiWan Mobile (Android) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=tw.com.watsons.app
This is our Watsons Malaysia Mobile (Android) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=com.watsons.mcommerce
PNS is our leading e-commerce website for every day items in Hong Kong. If you are testing functionalities that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
In Scope
=========
>https://www.pns.hk
>https://www10.pns.hk
>api.pns.hk
>Mobile app retail (Android and iOS)
This asset is specifically for Superdrug's subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In scope
=====================
>*.superdrug.com/
Out of scope
=====================
>https://appt.healthclinics.superdrug.com/
>https://healthclinics.superdrug.com/
This is one of our main perfumeries. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
In scope
=====================
>https://www.marionnaud.it/
>https://www.marionnaud.at/
>https://www.marionnaud.ch/
>https://www.marionnaud.ro/
>https://www.marionnaud.sk/
>https://www.marionnaud.cz/
>https://www.marionnaud.hu/
>https://app.marionnaud.it/
>https://app.marionnaud.at/
>https://app.marionnaud.ch/
>https://app.marionnaud.ro/
>https://app.marionnaud.sk/
>https://app.marionnaud.cz/
>https://app.marionnaud.hu/
>Mobile app retail (Android and iOS)
*Not eligible for bounty*
>\*.marionnaud.it/
>\*.marionnaud.at/
>\*.marionnaud.ch/
>\*.marionnaud.ro/
>\*.marionnaud.sk/
>\*.marionnaud.cz/
>\*.marionnaud.hu/
>https://www.marionnaud.it/blog/
>https://www.marionnaud.at/blog/
>https://www.marionnaud.ch/blog/
>https://www.marionnaud.ro/blog/
>https://www.marionnaud.sk/blog/
>https://www.marionnaud.cz/blog/
>https://www.marionnaud.hu/blog/
This is the API server for the www.watsons.com.hk website
This is our Watsons Singapore Mobile (Android) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=com.watsons.sg.android
This is the API server for the Watsons Philippines Mobile App
This is our online Slovakian perfumery. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This is our Watsons Indonesia Mobile (IOS) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/hk/app/watsons-id/id1184851346
This is the API server for the www.marionnaud.it e-commerce website.
This asset is specifically for Watsons TW's subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In Scope
=========
>*.watsons.com.tw/
This is our Dutch online retail mobile app. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This app is similar to other apps (Such as Superdrug). Please keep in mind that issues might be considered duplicates if it is reported on another website already.
Netherlands https://play.google.com/store/apps/details?id=nl.kruidvat.voordeelkaart
Belgium
https://play.google.com/store/apps/details?id=be.kruidvat.voordeelkaart
This is our Dutch online retail mobile app. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This app is similar to other apps (Such as Superdrug). Please keep in mind that issues might be considered duplicates if it is reported on another website already.
Netherlands
https://itunes.apple.com/nl/app/kruidvat-mobiele-app/id531631058
Belgium
https://apps.apple.com/be/app/kruidvat/id1151434781
This is our Watsons Thailand Mobile (Android) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=com.mtelnet.watson.thailand
This is our online retail platform. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This is our Belgium online Perfumery. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This website is similar to other websites (Such as Superdrug and Kruidvat). Please keep in mind that issues might be considered duplicates if it is reported on another website already.
This is the API server of the Kruidvat Mobile App in Belgium
This is the API server of the ICI Paris XL mobile app in Belgium
This is the API server for the superdrug.com website
This is the API server of The Perfume Shop mobile app
This subdomain is used to store static content for the www.watsons.com.tw e-commerce website.
This is our online Austrian perfumery. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This is the API server of the Marionnaud mobile app in Switzerland
This is our online Czech perfumery. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This is our online Italian perfumery. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This is our The Perfume Shop (Android) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=com.theperfumeshop.customer
This is our ICI Paris XL (iOS) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App link:
https://apps.apple.com/nl/app/ici-paris-xl-beauty/id1061895392
This asset is specifically for Kruidvat NL subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.kruidvat.nl/
This asset is specifically for Watsons Malaysia subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In Scope
=========
>*.watsons.com.my/
This subdomain is used to store static content for the www.watsons.com.sg e-commerce website.
This is our The Perfume Shop (iOS) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
Appstore Link
https://apps.apple.com/gb/app/the-perfume-shop/id1202206665
This is the API server for the www.watsons.co.th website
This is our Wordpress blog for Drogas Lithuania
This asset is specifically for Drogas LV subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.drogas.lv/
This is the API server for the old PNS environment
This asset is specifically for PNS's subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In Scope
=========
> *.pns.hk/
> *.parknshop.com/
This asset is specifically for Watsons HK's subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In Scope
=========
>*.watsons.com.hk/
This is our online Hungarian perfumery. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This is the API server of the Marionnaud mobile app in Slovakia
This subdomain is used to store static content for the www.pns.hk e-commerce website.
ICI Paris XL (subdomains)
This asset is specifically for ICI Paris XL's subdomain assets.
Please note that for subdomains (tier 3), will only pay out reports that have a high or critical severity.
In scope
=====================
>\*.iciparisxl.nl/
>\*.iciparisxl.be/
>\*.iciparisxl.lu/
This asset is specifically for PNS's subdomain assets.
Please note that for subdomains (tier 3), will only pay out reports that have a high or critical severity.
In Scope
=========
> \*.pns.hk/
> \*.parknshop.com/
This asset is specifically for Fortress's subdomain assets.
Please note that for subdomains (tier 3), will only pay out reports that have a high or critical severity.
In Scope
=========
> *.fortress.com.hk/
This subdomain is used to store static content for the www.watsons.com.my e-commerce website.
This is the API server for the www.marionnaud.fr website
This is our wordpress blog for Drogas Latvia
This is the API server of the Marionnaud mobile app in Italy
This is the API server for the Watsons Singapore Mobile App
This subdomain is used to store static content for the www.iciparisxl.nl e-commerce website
This is the API server of the Marionnaud mobile app in Romania
This asset is specifically for Watsons Indonesia subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In Scope
=========
>*.watsons.co.id
This is our Watsons Philippines Mobile (Android) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=com.mtelnet.watson.ph
This is our MoneyBack Mobile (iOS) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/hk/app/moneyback/id1230818544
This is our Watsons TaiWan Mobile (IOS) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/hk/app/%E5%B1%88%E8%87%A3%E6%B0%8F%E5%8F%B0%E7%81%A3/id477968775
Fortress is one of our leading e-commerce websites in Hong Kong and Macau.
Customers could shop for electrical appliances after paying their electricity bills. If you are testing functionalities that require you to be authenticated,
please ensure you register with your @wearehackerone.com email address.
This is the API server of the Drogas Lithuania mobile app
This is our online retail platform. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This asset is specifically for Watsons Philippines subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In Scope
=========
>*.watsons.com.ph/
This is the API server of the Watsons Vietnam Mobile App
This subdomain is used to store static content for the www.watsons.com.hk e-commerce website.
This is our online retail platform for health and beauty products in Singapore.
If you are testing a functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This is our Drogas (Android) app in Lithuania. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=lt.drogas.consumer
This is our online retail platform for health and beauty products in Taiwan.
If you are testing a functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This is our Marionnaud (iOS) app in Romania. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/ro/app/marionnaud-romania/id1021924260
This is the API server for the Watsons Thailand Mobile App
This subdomain is used to store static content for the www.superdrug.com e-commerce website
This is our Dutch online retail mobile app for Belgium customers. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This app is similar to other apps (Such as Superdrug). Please keep in mind that issues might be considered duplicates if it is reported on another website already.
App Link
https://play.google.com/store/apps/details?id=be.kruidvat.voordeelkaart
This subdomain is used to store static content for the www.watsons.com.ph e-commerce website.
This is our Drogas (iOS) app in Lithuania. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
This asset is specifically for Watsons TR' subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In scope
=====================
>\*.watsons.com.tr
This is the API server of the Marionnaud mobile app in Slovakia
This is our Watsons (iOS) app in Turkey. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
https://apps.apple.com/app/watsons-t%C3%BCrkiye/id1507132907
This is the API server of the Kruidvat Mobile App in the Netherlands
This is the API server of the Marionnaud mobile app in Czech Republic
This subdomain is used to store static content for the www.watsons.vn e-commerce website.
This subdomain is used to store static content for the www.marionnaud.it e-commerce website.
This is the API server of the Marionnaud mobile app in Austria
This is our Watsons Thailand Mobile (IOS) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/hk/app/watsons-th/id619935224
This is the API server for the www.watsons.co.id website
This is our wordpress blog for Drogas Latvia
This is our Turkish online retail platform for health and beauty products.
If you are testing a functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This is our online France perfumery. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This is our Watsons HongKong Mobile (IOS) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/hk/app/%E5%B1%88%E8%87%A3%E6%B0%8F%E9%A6%99%E6%B8%AF/id479512803
This is our Dutch online retail platform. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This website is similar to other websites (Such as Superdrug). Please keep in mind that issues might be considered duplicates if it is reported on another website already.
This asset is specifically for ICI Paris XL LU subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.iciparisxl.lu/
This asset is specifically for Marionnaud FR subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.marionnaud.fr/
This asset is specifically for Marionnaud IT subdomain assets.
Please note that for subdomains (tier 3); will only pay out reports that have a high or critical severity.
In Scope
=========
>*.marionnaud.it/
This is our Watsons Malaysia Mobile (IOS) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/hk/app/watsons-my/id1112796292
This is the API server of the ICI Paris XL mobile app in the Netherlands
This is the API server for the Watsons Malaysia Mobile App
This is our Fortress Mobile (Android) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=fortress.fortressapp
This is the new API server of The Perfume Shop mobile app
This is the API server of the Marionnaud mobile app in Switzerland
This is the API server for the Fortress Mobile App
This asset is specifically for Drogas' subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In scope
=====================
>\*.drogas.lv
>\*.drogas.lt
This is our Watsons Malaysia Mobile (Android) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=com.watsons.mcommerce
This is our mobile app subdomain for Fortress.
This is the API server of the ICI Paris XL mobile app in Belgium
This is our Watsons Singapore Mobile (IOS) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/hk/app/watsons-sg-the-official-app/id449412168
This is our online Romanian perfumery. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This subdomain is used to store static content for the www.iciparisxl.lu e-commerce website
This asset is specifically for Superdrug's subdomain assets.
Please note that for subdomains (tier 3), will only pay out reports that have a high or critical severity.
In scope
=====================
>*.superdrug.com/
Out of scope
=====================
>https://appt.healthclinics.superdrug.com/
>https://healthclinics.superdrug.com/
This is our online retail platform for health and beauty products in Vietnam. If you are testing a functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This is our Marionnaud (iOS) app in Switzerland. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/ch/app/id1486316902
This is our Marionnaud (Android) app in Switzerland. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=ch.marionnaud.customer
This is our Marionnaud (Android) app in Romania. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=ro.marionnaud.customer
This is our Marionnaud (iOS) app in Austria. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/gb/app/marionnaud-%C3%B6sterreich/id1114541888
This is our online retail platform for health and beauty products in Thailand.
If you are testing a functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This is our PNS Mobile (iOS) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/hk/app/parknshop/id840837558
This is the API server for the PNS Mobile App
This is our API Server for our PNS website (www.pns.hk)
This is our Dutch online retail mobile app for Belgium customers. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This app is similar to other apps (Such as Superdrug). Please keep in mind that issues might be considered duplicates if it is reported on another website already.
App Link
https://apps.apple.com/be/app/kruidvat/id1151434781
This is our Dutch online retail mobile app. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This app is similar to other apps (Such as Superdrug). Please keep in mind that issues might be considered duplicates if it is reported on another website already.
App Link
https://play.google.com/store/apps/details?id=nl.kruidvat.voordeelkaart
This is our Dutch online retail mobile app. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This app is similar to other apps (Such as Superdrug). Please keep in mind that issues might be considered duplicates if it is reported on another website already.
App Link
https://itunes.apple.com/nl/app/kruidvat-mobiele-app/id531631058
This is our MoneyBack Mobile (Android) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://apps.apple.com/hk/app/fortress/id1133110850
This asset is specifically for Moneyback's subdomain assets.
Please note that for subdomains (tier 3), will only pay out reports that have a high or critical severity.
In Scope
=========
> *.moneyback.com.hk/
The Perfume Shop (subdomains)
This asset is specifically for The Perfume Shop's subdomain assets.
Please note that for subdomains (tier 3), will only pay out reports that have a high or critical severity.
In scope
=====================
>\*.theperfumeshop.com/
This is our online Swiss perfumery. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This is the API Server for our MoneyBack Mobile App
This is our online Czech perfumery. If you are testing functionality that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This is the API server of the Marionnaud mobile app in Hungary
This is the API server of the Drogas Latvia mobile app.
This is our Wordpress blog for Drogas Latvia
This is the API server for the www.watsons.vn website
PNS is our leading e-commerce website for every day items in Hong Kong. If you are testing functionalities that requires you to be authenticated, please ensure you register with your @wearehackerone.com email address.
This is the API server for the www.watsons.com.sg website
This is the API server for the www.watsons.com.tw website
This is our Watsons Thailand Mobile (Android) app. Please make sure to consult our policy page to see which items are out of scope for mobile apps.
App Link
https://play.google.com/store/apps/details?id=com.mtelnet.watson.thailand
This asset is specifically for Watsons VN subdomain assets.
Please note that for subdomains (tier 3), will only handle reports that have a high or critical severity.
In Scope
=========
>*.watsons.vn/
This subdomain is used to store static content for the www.theperfumeshop.com e-commerce website
This is the API server for the www.watsons.com.ph website
This is the API server for the www.iciparisxl.lu website
This is the API server of the Drogas mobile app in Latvia