At Emmaüs, you can count on high-quality care. However, we aim for more than just compassionate support. We strive to help you achieve a successful recovery, maintain the best possible quality of life, and regain control over your daily life. Every day, more than 7,500 employees are committed to this mission. You can find us across 22 facilities in the province of Antwerp. We take the security of our systems and the protection of sensitive information very seriously. Despite our best efforts, vulnerabilities may still exist. That is why we welcome feedback from security researchers, ethical hackers, and the wider community. If you discover a potential security issue in one of our systems, applications, or services, we encourage you to report it to us responsibly. By working together, we can better protect our patients, employees, and partners. Your responsible disclosure helps us improve our security. We greatly appreciate your efforts and collaboration in keeping Emmaüs safe.
This is a responsible disclosure program without bounties.
By participating in this program, you agree to:
- Respect the Community Code of Conduct
- Respect the Intigriti Terms and Conditions
- Respect the scope of the program
- Not discuss or disclose vulnerability information without prior written consent (including PoC's on YouTube and Vimeo)
Introduction
This program applies to the Emmaüs systems, services, and endpoints included in our published list of assets.
We do not offer financial or material rewards for reported vulnerabilities. However, we highly value the contributions of security researchers and appreciate their efforts in helping us improve our security.
Assets
- Any asset that is not listed in the Assets section, is out of scope for this program
Application
- Self-XSS that can't be used to exploit other users
- Verbose messages/files/directory listings without disclosing any sensitive information
- CORS misconfiguration on non-sensitive endpoints
- Missing cookie flags
- Missing security headers
- Cross-site Request Forgery with no or low impact
- Presence of autocomplete attribute on web forms
- Reverse tabnabbing
- Bypassing rate-limits or the non-existence of rate-limits.
- Best practices violations (password complexity, expiration, re-use, etc.)
- Clickjacking without proven impact/unrealistic user interaction
- Sessions not being invalidated (logout, enabling 2FA, etc.)
- Tokens leaked to third parties
- Anything related to email spoofing, SPF, DMARC or DKIM
- Content injection without being able to modify the HTML
- Email bombing
- HTTP Request smuggling without any proven impact
- Homograph attacks
- XMLRPC enabled
- Banner grabbing/Version disclosure
- Not stripping metadata of files
- Same-site scripting
- Arbitrary file upload without proof of the existence of the uploaded file
- Blind SSRF without proven business impact (pingbacks aren't sufficient)
- Disclosed/misconfigured Google Maps API keys
- Host header injection without proven business impact
- Insecure TLS/SSL v1.1 configurations on mail endpoints
General
- In case that a reported vulnerability was already known to the company from their own tests, it will be flagged as a duplicate
- Theoretical security issues with no realistic exploit scenario(s) or attack surfaces, or issues that would require complex end user interactions to be exploited
- Spam, social engineering and physical intrusion
- DoS/DDoS attacks or brute force attacks
- Vulnerabilities that only work on software that no longer receive security updates, unless the specific software version was detected
- Attacks requiring physical access to a victim's computer/device, man in the middle or compromised user accounts
- Reports that state that software is out of date/vulnerable without a proof-of-concept
This program follows Intigriti's triage standards based on the proof of concept.
Can we get credentials for any of the ESS endpoints?
Credentials are available per request for the following ESS endpoints:
- azvk-ess.emmaus.be
- astm-ess.emmaus.be
Where can we get credentials for the other endpoints/apps?
We currently don’t offer any credentials to test other apps.
For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.
It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.






























