NxtPort builds the next digital link in the digital port infrastructure of the Port of Antwerp-Bruges, developing platforms to make the port faster, safer and more efficient. NxtPort welcomes security researchers and the broader security community to help us identify and responsibly disclose vulnerabilities in our systems. Through this Vulnerability Disclosure Program (VDP), we encourage the reporting of potential security issues that could impact the confidentiality, integrity, or availability of our services. Our goal is to work collaboratively with researchers to investigate and remediate valid findings, helping us maintain a secure and resilient digital ecosystem for the Port of Antwerp-Bruges community. We ask researchers to act responsibly, respect our disclosure guidelines, and avoid activities that could disrupt services or compromise user data. If you discover a vulnerability, please submit it through this program. We appreciate your efforts in helping us improve the security of NxtPort's platforms and services.
This is a responsible disclosure program without bounties.
By participating in this program, you agree to:
- Respect the Community Code of Conduct
- Respect the Intigriti Terms and Conditions
- Respect the scope of the program
- Not discuss or disclose vulnerability information without prior written consent (including PoC's on YouTube and Vimeo)
Validation times
We will validate all submissions within the below timelines, once your submission has been verified by Intigriti.
Submissions validated outside of this may be awarded a €25 bonus.
| Vulnerability Severity | Time to validate |
|---|---|
| Exceptional | 2 Working days |
| Critical | 2 Working days |
| High | 5 Working days |
| Medium | 15 Working days |
| Low | 15 Working days |
This remains at the discretion of NxtPort to award.
We are happy to announce our VDP program! We've done our best to clean up our known issues and now would like to request your help to spot the ones we missed!
Our worst-case scenarios are:
We are particularly interested in vulnerabilities that could lead to:
- Unauthorized access to systems, applications, or sensitive information.
- Compromise of customer, partner, or operational data.
- Authentication and authorization bypasses.
- Privilege escalation.
- Remote code execution.
- Exposure of secrets, credentials, or API keys.
- Vulnerabilities that could impact the availability or integrity of critical port community services.
- Cross-tenant access or data leakage between organizations.
- Supply chain or dependency-related security weaknesses.
Any useful infrastructure information:
Primary domain:
nxtport.com
Cloud platform:Microsoft Azure
- Modern authentication mechanisms are used where applicable.
- Public APIs may be available through API gateways and protected authentication flows.
- Production environments may process business-critical information related to port community services.
Please avoid actions that could disrupt service availability, impact other users, alter data, or affect operational processes.
Application
- Wordpress usernames disclosure
- Pre-Auth Account takeover/OAuth squatting
- Self-XSS that can't be used to exploit other users
- Verbose messages/files/directory listings without disclosing any sensitive information
- CORS misconfiguration on non-sensitive endpoints
- Missing cookie flags
- Missing security headers
- Cross-site Request Forgery with no or low impact
- Presence of autocomplete attribute on web forms
- Reverse tabnabbing
- Bypassing rate-limits or the non-existence of rate-limits.
- Best practices violations (password complexity, expiration, re-use, etc.)
- Clickjacking without proven impact/unrealistic user interaction
- CSV Injection
- Sessions not being invalidated (logout, enabling 2FA, etc.)
- Tokens leaked to third parties
- Anything related to email spoofing, SPF, DMARC or DKIM
- Content injection without being able to modify the HTML
- Username/email enumeration
- Email bombing
- HTTP Request smuggling without any proven impact
- Homograph attacks
- XMLRPC enabled
- Banner grabbing/Version disclosure
- Not stripping metadata of files
- Same-site scripting
- Subdomain takeover without taking over the subdomain
- Arbitrary file upload without proof of the existence of the uploaded file
- Blind SSRF without proven business impact (pingbacks aren't sufficient)
- Disclosed/misconfigured Google Maps API keys
- Host header injection without proven business impact
General
- In case that a reported vulnerability was already known to the company from their own tests, it will be flagged as a duplicate
- Theoretical security issues with no realistic exploit scenario(s) or attack surfaces, or issues that would require complex end user interactions to be exploited
- Spam, social engineering and physical intrusion
- DoS/DDoS attacks or brute force attacks
- Vulnerabilities that only work on software that no longer receive security updates
- Attacks requiring physical access to a victim's computer/device, man in the middle or compromised user accounts
- Recently discovered zero-day vulnerabilities found in in-scope assets within 14 days after the public release of a patch or mitigation may be reported, but are usually not eligible for a bounty
- Reports that state that software is out of date/vulnerable without a proof-of-concept
This program follows Intigriti's triage standards based on the proof of concept.
What should I report?
Please report any vulnerability that could impact the confidentiality, integrity, or availability of NxtPort systems, applications, APIs, or data.
What should I avoid during testing?
Please do not:
Access, modify, or delete data that does not belong to you.
Perform denial-of-service (DoS/DDoS) attacks.
Use social engineering, phishing, or physical attacks.
Disrupt services used by customers or partners.
Conduct automated scanning that may negatively affect service availability.
Will I receive a reward?
This is a Vulnerability Disclosure Program (VDP). While vulnerability reports are highly appreciated, rewards are not guaranteed unless explicitly stated otherwise.
What happens after I submit a report?
Our security team will review your submission, assess its validity and severity, and may contact you for additional information. We will keep you informed about the status of your report.
How long should I wait before disclosing a vulnerability publicly?
Please do not publicly disclose vulnerabilities until NxtPort has investigated and remediated the issue, or has explicitly agreed to disclosure.
Am I covered by Safe Harbor?
Yes. Researchers acting in good faith, following the program rules, and avoiding privacy violations, service disruption, or data destruction are covered by our Safe Harbor policy.
What if I accidentally access sensitive information?
Stop testing immediately, do not copy, store, modify, or share the information, and report the issue to us as soon as possible.
For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.
It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.






























