Description

Soundtrack Your Brand offers music streaming services for businesses. We serve small customers like the café around the corner or larger brands like McDonald’s. Through our service customers have total control over the music and can manage locations across the world. We provide a wide variety of playback options, from mobile apps to custom hardware, that our customers use to play music at their venues. They manage their account, music and locations via our web app.

Bounties
Low
0.1 - 3.9
Medium
4.0 - 6.9
High
7.0 - 8.9
Critical
9.0 - 9.4
Exceptional
9.5 - 10.0
Tier 1
100
500
1,000
2,500
3,500
Tier 1
€100 - €3,500
Tier 2
50
250
750
1,750
2,500
Tier 2
€50 - €2,500
Rules of engagement
Not applicable
Not applicable
max. 20 requests /sec
Not applicable

By participating in this program, you agree to:

  • Respect the Community Code of Conduct
  • Respect the Intigriti Terms and Conditions
  • Respect the scope of the program
  • Not discuss or disclose vulnerability information without prior written consent (including PoC's on YouTube and Vimeo)
Domains
iOS

The iOS Player app that allows you to browse and play music.

In order to use the iOS Player you will need a pairing code that you can obtain through https://business.soundtrackyourbrand.com using the test credentials.

https://www.youtube.com/watch?v=y7HGAtsB6Tg

iOS

The iOS Remote that allows you to remotely control your Soundtrack Players.

In order to use the iOS Remote you will need a remote code that you can obtain through https://business.soundtrackyourbrand.com using the test credentials.

https://www.youtube.com/watch?v=cmAe1kRvOeY

Our public API. Used by us as well as third parties. You can use your regular login token to authenticate.

Docs: https://developer.soundtrackyourbrand.com/api
GraphQL Explorer: https://api.soundtrackyourbrand.com/v2/explore

Please use one of the claimed test credentials. In order to use the API you can login using your claimed credentials (via loginUser) and use the token you get back to issue API calls.

Severity assessment

This program follows Intigriti's contextual CVSS standard

FAQ

Where can we get credentials for https://business.soundtrackyourbrand.com?

You can use the get credentials button in the right top corner to request credentials that are ready to use! Feel free to reach out to support if you have any issue with these credentials.

These credentials will give you access to two Soundtrack accounts that you must use for testing, each with access to a different tenant. They have been preconfigured with a number of locations and sound zones. If you want to test functionality relating to music playback, go ahead and pair one of those zones to one a player.

All aboard!
Please log in or sign up on the platform

For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.

It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.