1Introduction
At Xoxoday, protecting customer data and maintaining trust are among our highest priorities. We deeply value the contributions of the security research community in helping us identify and address potential vulnerabilities across our products and services.
We believe that responsible disclosure of security vulnerabilities plays a critical role in maintaining the security and privacy of our users. We welcome security researchers to report vulnerabilities they discover in accordance with this policy. Researchers who submit valid vulnerabilities that fall within the scope of this program may be eligible for rewards based on the severity and impact of the finding.
2Safe Harbor
Xoxoday welcomes security research conducted in good faith and in accordance with this policy. Activities performed consistent with these guidelines will be considered authorized.
Researchers participating in this program must:
- Avoid accessing, modifying, or deleting data belonging to other users.
- Avoid actions that could disrupt services, impact system availability, or degrade user experience.
- Limit testing to the minimum necessary to validate a vulnerability.
- Refrain from social engineering, phishing, physical attacks, or any activity that violates applicable laws.
Xoxoday will not pursue legal action against researchers who act in good faith and comply with this policy.
3How it works
Reach out to us at cs@xoxoday.com to raise a ticket if you notice any potential security issue whilst meeting all the required criteria in our policy.
Upon receiving a report, our security team will acknowledge receipt and begin the validation process. The reported issue will be assessed for authenticity, severity, and impact.
Post validation, steps will be taken to fix the security issue in accordance with our security policies. Researchers may be contacted for additional information during the review process if required.
The owner of the ticket will be informed once the issue is resolved and any applicable reward determination has been completed.
4Eligibility
To be eligible for a reward, the following requirements must be met by you:
- You must be the first person to report a vulnerability to Xoxoday.
- The issue must impact any one of the applications listed under our defined scope.
- The issue must fall under the 'Qualifying' bugs listed.
- Publishing of vulnerability information in the public domain is not allowed.
- Any information about the vulnerability issue must be kept confidential until the issue is resolved.
- No privacy policies set by Xoxoday must be violated when performing security testing.
- Modification or deletion of unauthenticated user data, disruption of production servers, or any form of degradation to user experience is completely prohibited.
Violation of any of these rules can result in ineligibility or removal from the Xoxoday bug bounty program.
5Guidelines
- Use only the identified channel cs@xoxoday.com to report any security vulnerability.
- While raising the ticket, ensure that the description and potential impact of the vulnerability is clearly mentioned.
- Detailed instructions on the steps to be followed to reproduce the vulnerability must also be included.
- A complete Video POC should mandatorily be attached showing all the steps and information.
- Details about the scope and qualification criteria are mentioned below.
6Scope
- Website: Xoxoday Store (https://stores.xoxoday.com)
- Out-of-Scope websites: Staging subdomains, any other subdomain which is not connected to xoxoday.com
7Qualifying Vulnerabilities
Any design or implementation issue that substantially affects the confidentiality or integrity of user data is likely to be in scope for the program. Common examples include:
- Cross-site Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- Server-Side Request Forgery (SSRF)
- SQL Injection
- Server-Side Remote Code Execution (RCE)
- XML External Entity Attacks (XXE)
- Access Control Issues (Insecure Direct Object Reference Issues, Privilege Escalation, etc.)
- Exposed Administrative Panels that don't require login credentials
- Directory Traversal Issues
- Local File Disclosure (LFD) and Remote File Inclusion (RFI)
- Payments Manipulation
- Server-side code execution bugs
8Non-Qualifying Vulnerabilities
- Open-Redirects: 99% of open redirects have low security impact. For the rare cases where the impact is higher, e.g., stealing OAuth tokens, we do still want to hear about them.
- Reports that state that software is out of date/vulnerable without a Proof of Concept.
- Host header issues without an accompanying POC demonstrating vulnerability.
- XSS issues that affect only outdated browsers.
- Stack traces that disclose information.
- Clickjacking and issues only exploitable through clickjacking.
- CSV injection.
- Best practices concerns.
- Highly speculative reports about theoretical damage. Be concrete.
- Self-XSS that cannot be used to exploit other users.
- Vulnerabilities as reported by automated tools without additional analysis as to how they're an issue.
- Reports from automated web vulnerability scanners (Acunetix, Burp Suite, Vega, etc.) that have not been validated.
- Denial of Service Attacks.
- Brute Force Attacks.
- Reflected File Download (RFD).
- Physical or social engineering attempts (this includes phishing attacks against Xoxoday employees).
- Content injection issues.
- Cross-site Request Forgery (CSRF) with minimal security implications (Logout CSRF, etc.).
- Missing autocomplete attributes.
- Missing cookie flags on non-security-sensitive cookies.
- Issues that require physical access to a victim's computer.
- Missing security headers that do not present an immediate security vulnerability.
- Fraud Issues.
- Recommendations about security enhancement.
- SSL/TLS scan reports (this means output from sites such as SSL Labs).
- Banner grabbing issues (figuring out what web server we use, etc.).
- Open ports without an accompanying POC demonstrating vulnerability.
- Recently disclosed vulnerabilities. We need time to patch our systems just like everyone else – please give us two weeks before reporting these types of issues.
9Reward
Bug Bounty rewards will be paid in the form of popular gift cards. The value of the gift card will depend upon the severity, business impact, exploitability, and quality of the reported vulnerability. Reward amounts may also take into consideration the completeness of the report, quality of reproduction steps, and supporting evidence provided.
| Bug Severity | Reward Value |
|---|---|
| High | $50 |
| Medium | $25 |
| Low | $10 |
10Duplicate Report Policy
Rewards will be issued only for the first valid report of a vulnerability. Subsequent reports of the same issue may be considered duplicates and may not be eligible for rewards.
Xoxoday reserves the right to determine whether submissions are duplicate, related, or based on the same underlying root cause. Such determinations will be made at Xoxoday's sole discretion.
11Disclosure Policy
Researchers must not publicly disclose any vulnerability information before the issue has been resolved by Xoxoday. Any information relating to a reported vulnerability must be kept confidential until remediation is complete and disclosure has been approved by Xoxoday.
12Note
The final decision on bug eligibility, severity classification, duplicate determination, and rewarding will be made by Xoxoday. The program exists completely at the firm's discretion and has the provision to be modified, suspended, or canceled at any time.
Report vulnerabilities to
cs@xoxoday.com