Security & Vulnerability Disclosure

Found a security issue? Email security@jumpseller.com. Our machine-readable contact is at /.well-known/security.txt.

Jumpseller runs an e-commerce platform that thousands of merchants sell on. No technology is perfect, and we believe that working with skilled security researchers is how weaknesses get found. If you believe you have found a security issue in our product or service, we want to hear about it before anyone else does, and we will work with you until it is fixed.

How to report

Email security@jumpseller.com. This is the address published in our security.txt file, per RFC 9116, and it is monitored by our engineering team.

You can also submit through our Open Bug Bounty programme, which accepts both private and public submissions and handles triage for non-intrusive findings: cross-site scripting, open redirects, cross-site request forgery and improper access control. Email is faster for anything else.

To help us triage quickly, please include:

  • The affected URL, endpoint or component, and the store code you tested against.
  • A description of the issue and the impact you believe it has.
  • Steps to reproduce it, ideally with a minimal proof of concept.
  • Any accounts or tokens you used, so we can find the requests in our logs.

Rewards

We pay for original, in-scope vulnerabilities. Every report is assessed on criticality, impact, and the risk to our merchants and to us. The figures below are the lower bounds for each severity level:

  • Low — 25 to 50 USD
  • Medium — 60 to 150 USD
  • High — 300 to 500 USD
  • Critical — 1,500 to 2,500 USD

Rewards scale with impact and ingenuity, from an unlikely low-sensitivity XSS to a deep, novel remote code execution or credential stuffing chain. We may grant bonuses or larger rewards for critical vulnerabilities, more creative exploits and more insightful reports. One reward per bug: the first discovery claims it, and ties break toward the better report.

What we will do

  • Acknowledge your report within 3 business days.
  • Tell you whether we have reproduced it, and our assessment of the severity, within 10 business days.
  • Keep you updated while we work on a fix, and tell you when it ships.
  • Credit you publicly when the fix is out, if you want to be credited.

Scope

In scope:

  • Our websites: jumpseller.com and our regional domains.
  • The merchant admin, at <store_code>.jumpseller.com/admin.
  • Storefronts, at <store_code>.jumpseller.com.
  • The API at api.jumpseller.com, and our OAuth2 server.
  • Apps and themes developed by Jumpseller.

Test against a store you created yourself. Start a free trial, and take the store code, login and auth token from Account Options in the admin. Never test against a store you do not own, whether it is on *.jumpseller.com or on a merchant's own domain. If you notice something on a live store without going looking for it, report it to us and stop there.

Out of scope:

  • Content, theme code, apps or configuration authored by a merchant on their own store. Report those to the merchant; if you cannot reach them, tell us and we will pass it on.
  • Third-party services we integrate with. Report those to their owners.
  • Denial of service, rate limiting, spamming, and volumetric testing.
  • Social engineering of our staff, merchants or customers, and physical attempts against Jumpseller property.
  • Anything that requires a compromised device or a malicious app already installed on it, and self-XSS.
  • Raw scanner output, or missing hardening headers, without a demonstrated attack.

Issues we already know about

These are known, so they will not earn a reward:

  • CSRF tokens are not enabled on some admin controllers.
  • XSS originating from a store's own admin panel. A store administrator can already rewrite that storefront's HTML, so this crosses no boundary. XSS from a storefront into the admin panel is in scope, and we do want it.
  • Email addresses are not validated everywhere, deliberately, for business reasons. The denial of service this allows, and email flooding, are known.
  • Click-jacking on jumpseller.com: our CDN does not support the custom headers that would prevent it.

Rules of engagement and safe harbour

If you follow this policy in good faith, we will not pursue or support legal action against you for your research, and we will treat it as authorised under applicable computer misuse law. In return, we ask that you:

  • Stop as soon as you have confirmed a vulnerability. Do not pivot, escalate, or access more data than you need to demonstrate it.
  • Never access, modify, export or retain merchant or customer data. If you encounter personal data, stop and tell us immediately.
  • Do not disrupt our services, and do not run automated scans at a rate that affects other users.
  • Give us reasonable time to fix the issue before disclosing it. We ask for 90 days from your report, or until a fix ships, whichever comes first. If you believe the issue is being actively exploited, say so and we will move faster.

Acknowledgments

Thank you to the researchers who have reported issues to us responsibly. Reports handled through Open Bug Bounty are listed on our Open Bug Bounty profile. If you have reported an issue by email and would like to be named here, let us know.

Not a security issue?

For account, billing or store problems, contact Support. For copyright and intellectual property claims, see our DMCA notice and takedown procedure. For privacy and data protection requests, see our Terms of Service.

Report a security vulnerability

security@jumpseller.com

Entre na sua loja

Esqueceu a sua Password?

Esqueceu a sua Password?

Regressar a Iniciar Sessão