Description

Booksy is a booking and marketplace platform for the beauty and wellness industry, connecting customers with local service providers (hair salons, barbershops, nail salons, spas, massage therapists, and similar businesses). Booksy is committed to protecting the security of its platform and the data of its users. We operate a Responsible Disclosure Program that invites security researchers and users to report potential vulnerabilities they discover, reflecting our commitment to transparency and continuous security improvement. If you believe you've found a security vulnerability, please feel free to report it. First line of verification is Intigriti triage, then reports go to our internal Security Team at Booksy.

Bounties

This is a responsible disclosure program without bounties.

Rules of engagement
Required
Place into User-Agent header your Intigriti email
max. 3 requests /sec
Not applicable

By participating in this program, you agree to:

By enrolling in the program, you confirm that you have read and understood the terms outlined herein and agree to comply with them, as well as with any other applicable terms and conditions related to your participation on the Intigriti platform and associated collaborations.

Program Rules

  1. Huge scans using automated tools are strictly prohibited. If your tests have a negative impact on an element of our platform we might remove you from the VDP.
  2. Act responsibly and avoid any actions that could violate user privacy, compromise or destroy data, or disrupt or impair the functionality of our services. Only engage with accounts that belong to you or where you have received clear permission from the account owner.
  3. Vulnerabilities must be discovered by you personally. Reports based on findings from others will not be accepted.
  4. Do not store Booksy’s non-public data (except the data necessary to document and report the presence of a potential vulnerability);
  5. You must not currently work for Booksy or any of its affiliates, nor have been employed by them within the 12 months prior to participating in this program.
  6. You are required to follow these guidelines both during your investigation and when submitting your vulnerability report.
  7. Any user data accessed during testing must be anonymized in your submission and permanently removed from your systems without delay.
  • Respect the Community Code of Conduct
  • Respect the Intigriti Terms and Conditions
  • Respect the scope of the program
  • Not discuss or disclose vulnerability information without prior written consent (including PoC's on YouTube and Vimeo)

What is also forbidden:

  • Any activity that could harm Booksy or its users (such as spam, brute-force attacks, or denial-of-service attacks) is prohibited. If you notice that your testing is causing unintended impact on Booksy systems or users, you must immediately stop the test and notify us.
  • Any form of physical attack against Booksy employees, property, or data centers is strictly prohibited.
  • Social engineering attacks (including phishing, vishing, smishing) targeting Booksy’s support teams, employees, contractors, or users are not allowed under any circumstances.
  • You must not violate any applicable laws or breach any agreements in the process of discovering or reporting vulnerabilities.
  • Please do not scan automatically. Keep request rate below 3 req/s

Confidentiality Commitment

You are required to treat all information obtained through your participation in the program as strictly confidential. This includes taking appropriate safeguards to protect such information, regardless of the format in which it was provided ("Confidential Information").
You may use Confidential Information solely for the purpose of participating in the program and must implement suitable measures to keep it secure and prevent any unauthorized access or disclosure.
You will be held responsible for any direct or indirect harm that Booksy suffers as a result of unauthorized disclosure of Confidential Information, including—but not limited to—actual damages, lost profits, and any legal or enforcement costs related to the breach.

Personal Data

  • "Personal Data" refers to any information that directly or indirectly identifies an individual.
  • If you come into possession of Personal Data while participating in the program, you act as a data processor, and Booksy remains the data controller.
  • You are not permitted to engage any third-party processors.
  • Once you obtain any Personal Data controlled by Booksy, you are required to delete it promptly, in line with the purpose and principles of the program.
  • You confirm that you are capable of meeting the obligations of a data processor as defined in Article 28 of the General Data Protection Regulation (GDPR).

Validation times

Vulnerability Severity Time to validate
Exceptional 3 Working days
Critical 3 Working days
High 5 Working days
Medium 15 Working days
Low 15 Working days
In scope

Introduction

We are happy to announce our Responsible Disclosure Policy program! We've done our best to clean up our known issues and now would like to request your help to spot the ones we missed!

Our worst-case scenarios are:

  • Accessing unauthorized data / functions, especially related to PII
  • Creating a financial loss for Booksy or our customers

Any useful infrastructure information:

Please do not perform any DoS/DDoS attacks, brute force attacks, spam, social engineering and physical intrusion.

Out of scope

Domains

  • Any domain that is not listed in the Domains section, is out of scope for this program

Application

  • BAC / IDOR vulnerabilities, that are exploited within a single salon are considered Out Of Scope. (For e.g. Staffer uploading pictures to portfolio, which should be done only by Reception or above.) These vulnerabilities will be accepted only if they are related to payments, financial data, PII or have proven significant security impact.
  • API key disclosure without proven business impact
  • Bugs in content/services that are not owned/operated by Booksy
  • Vulnerabilities affecting users of outdated or unsupported browsers or platforms
  • Missing CAPTCHA (it might be not enabled on test environments)
  • Password complexity or account recovery policies
  • Username / email enumeration
  • Issues without clearly identified security impact, such as clickjacking on a static website, missing security headers, or descriptive error messages, cookie flags, lack of CSP
  • Pre-Auth Account takeover/OAuth squatting
  • Self-XSS that can't be used to exploit other users
  • Verbose messages/files/directory listings without disclosing any sensitive information
  • CORS misconfiguration on non-sensitive endpoints
  • Missing cookie flags
  • Missing security headers
  • Cross-site Request Forgery with no or low impact
  • Presence of autocomplete attribute on web forms
  • Reverse tabnabbing
  • Bypassing rate-limits or the non-existence of rate-limits.
  • Best practices violations (password complexity, expiration, re-use, etc.)
  • Clickjacking without proven impact/unrealistic user interaction
  • CSV Injection
  • Sessions not being invalidated (logout, enabling 2FA, etc.)
  • Tokens leaked to third parties
  • Anything related to email spoofing, SPF, DMARC or DKIM
  • Content injection without being able to modify the HTML
  • HTML injections without proven impact
  • Username/email enumeration
  • Email bombing
  • HTTP Request smuggling without any proven impact
  • Homograph attacks
  • XMLRPC enabled
  • Banner grabbing/Version disclosure
  • Not stripping metadata of files
  • Same-site scripting
  • Subdomain takeover without taking over the subdomain
  • Arbitrary file upload without proof of the existence of the uploaded file
  • Blind SSRF without proven business impact (pingbacks aren't sufficient)
  • Disclosed/misconfigured Google Maps API keys
  • Host header injection without proven business impact
  • Weak SSL/TLS Cipher Suites
  • Use of a known-vulnerable library without evidence of exploitability
  • Attacks requiring physical access to a user's unlocked device

General

  • In case that a reported vulnerability was already known to the company from their own tests, it will be flagged as a duplicate
  • Theoretical security issues with no realistic exploit scenario(s) or attack surfaces, or issues that would require complex end user interactions to be exploited
  • Spam, social engineering and physical intrusion
  • DoS/DDoS attacks or brute force attacks
  • Vulnerabilities that only work on software that no longer receive security updates
  • Attacks requiring physical access to a victim's computer/device, man in the middle or compromised user accounts
  • Recently discovered zero-day vulnerabilities found in in-scope assets within 14 days after the public release of a patch or mitigation may be reported, but are usually not eligible for a bounty
  • Reports that state that software is out of date/vulnerable without a proof-of-concept
  • Sending vulnerability reports using automated tools without validation
  • Theoretical security issues with no realistic exploit scenario(s) or attack surfaces, or issues that would require complex end user interactions to be exploited

Mobile

  • Shared links leaked through the system clipboard
  • Any URIs leaked because a malicious app has permission to view URIs opened
  • The absence of certificate pinning
  • Sensitive data in URLs/request bodies when protected by TLS
  • Lack of obfuscation
  • Path disclosure in the binary
  • Lack of jailbreak & root detection
  • Crashes due to malformed URL Schemes
  • Lack of binary protection (anti-debugging) controls, mobile SSL pinning
  • Snapshot/Pasteboard leakage
  • Runtime hacking exploits (exploits only possible in a jailbroken environment)
  • API key leakage used for insensitive activities/actions
Severity assessment

This program follows Intigriti's triage standards based on the proof of concept.

FAQ

Where can we get credentials for the app?

You can self-register on the application but please don’t forget to use your @intigriti.me address.

All aboard!
Please log in or sign up on the platform

For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.

It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.

Overall stats
submissions received
1
average payout
N/A
accepted submissions
N/A
total payouts
N/A
Last 90 day response times
avg. time first response
< 6 days
avg. time to triage
< 6 days
Activity
8/13
Booksy
closed a submission
8/7
logo
smaranchand
created a submission
7/23
Booksy VDP
launched