Responsible Disclosure Policy

Protecting customer data comes first at Lodgix. If you are a security researcher and you find a problem, we want to hear about it. This policy explains how to report it.

The responsible disclosure of security vulnerabilities helps us ensure the security and privacy of all our users. If you believe you have discovered a potential security vulnerability or bug within any of Lodgix Security’s publicly available resources, sites, or one of our services or products, we would like you to let us know as quickly as possible by emailing our Security Team at security@lodgix.com.

Terms and conditions

To comply with the terms in this Responsible Disclosure Policy:

  • Do not execute or attempt to execute any "Denial of Service" attack.
  • Do not post, transmit, upload, link to, send or store any malicious software.
  • Do not test what would result in sending unsolicited or unauthorized junk mail, spam or other forms of unsolicited messages.
  • Do not run automated scans without checking with Lodgix first.
  • Do not test in a manner that would corrupt the operation of Lodgix solutions.
  • Do not use social engineering techniques.
  • Do not test third-party applications, websites or services that integrate with or link to Lodgix properties.
  • Do not publicly disclose any vulnerability before 30 days after the vulnerability is resolved by Lodgix and not without Lodgix's prior written consent, and do not include any sensitive data in the disclosed vulnerability.
  • Remove all data and sensitive information you got from the analysis once the report is submitted.

Response times

Lodgix will make a best effort to meet the following response targets for researchers participating in our program:

  • Time to first response (from report submit): 2 business days
  • Time to triage (from report submit): 2 business days
  • We'll try to keep you informed about our progress throughout the process

For targets which are outside of our core regions, time to resolution may take longer. We will aim to communicate this ahead of time.

Vulnerabilities accepted

Accepted, in-scope vulnerabilities include, but are not limited to:

  • Injection vulnerabilities
  • Broken authentication and session management
  • Cross site scripting (XSS)
  • Remote code execution
  • Insecure direct object reference
  • Sensitive data exposure
  • Security misconfiguration
  • Missing function level access control
  • Using components with known vulnerabilities
  • Directory or path traversal
  • Exposed credentials

Out of scope vulnerabilities

Certain vulnerabilities are considered out of scope for the Responsible Disclosure Program, including but not limited to:

  • Social engineering attacks
  • Account enumeration using brute-force attacks
  • Weak password policies and password complexity requirements
  • Missing HTTP security headers which do not lead to a vulnerability
  • Reports from automated tools or scans
  • Presence of autocomplete attribute on web forms
  • Missing function level access control
  • Reports of SSL/TLS issues, best practices or insecure ciphers
  • Self-exploitation attacks
  • Test versions of applications
  • Mail configuration issues including SPF, DKIM, DMARC settings
  • Clickjacking on pages with no sensitive actions
  • Cross-site request forgery (CSRF) on unauthenticated forms or forms with no sensitive actions
  • Attacks requiring MITM or physical access to a user's device
  • Previously known vulnerable libraries without a working proof of concept
  • Comma separated values (CSV) injection without demonstrating a vulnerability
  • Any activity that could lead to the disruption of our service (DoS)
  • Content spoofing and text injection issues without showing an attack vector or the ability to modify HTML or CSS
  • Rate limiting or brute-force issues on non-authentication endpoints
  • Missing best practices in Content Security Policy
  • Missing HttpOnly or Secure flags on cookies
  • Vulnerabilities only affecting users of outdated or unpatched browsers
  • Software version disclosure, banner identification issues, or descriptive error messages or headers (e.g. stack traces, application or server errors)
  • Tabnabbing
  • Open redirect, unless an additional security impact can be demonstrated
  • Issues that require unlikely user interaction
  • Solutions affected by known CVEs published less than 30 days ago

In scope

  • Domains: lodgix.com, *.lodgix.com and any other Lodgix branded domain or service
  • Other: Lodgix mobile applications

Awarding process

An internal monthly committee will be accountable to analyze and decide about rewarding. Only CRITICAL and HIGH vulnerabilities that have been resolved might receive an award, and it is solely a decision by Lodgix.

Legal

By submitting a report to Lodgix, you acknowledge that you have read and agreed to these terms. You also warrant and represent to Lodgix that you are the sole creator of the submission and you hereby grant Lodgix the permission to use, reproduce, copy, modify and otherwise dispose of your submission in a manner as Lodgix sees fit.

You acknowledge and agree that you shall not use your relationship with Lodgix for any marketing or financing purpose or as reference in any personal or professional presentation, documentation or other material, or in any way utilize (neither on the Internet nor in any other way communicate to the public) any trade name, business name, logotype or trade mark of Lodgix.

Thank you for helping keep Lodgix and our users safe.