Alasco GmbH - Bug Bounty Program
Make your real estate projects more successful by managing costs, profits and ESG data from your assets in one software.
Reward
Program
Hacktivity
About Alasco GmbH
Alasco offers state of the art software for financial controlling and ESG management.
Security is very important to us and this Bug Bounty program shall help us meet highest industry standards to offer the most secure service and experience to all parties.
Program Rules
Attention: Business Continuity and Testing Conduct
Maintaining uninterrupted service for our users and partners is absolutely critical. All security testing must be performed with extreme care to avoid any form of business disruption. This includes actions that could degrade performance, interrupt service availability, or affect real customers.
Researchers are expected to act responsibly at all times and prioritize the stability, integrity, and security of Alasco systems above all else. If in doubt, stop testing immediately and seek clarification through the platform’s report discussion thread before proceeding.
Testing Policy and Responsible Disclosure
The below two rule sets form the core foundation of the Alasco Vulnerability Reward Program.
They are designed to protect business continuity, user data, and testing integrity.
- Priority Zero Rules are global and non-negotiable. They apply to all testing activities across all targets and take precedence over any other instruction or rule.
- Target-specific Program Rules define additional, per-target constraints — such as testing windows, rate limits, allowed endpoints, or isolated environments — to ensure safe and controlled testing for specific systems.
All researchers must review and follow both rule sets before starting any testing.
Violating either may result in disqualification of reports, revocation of bounty eligibility, or, in severe cases, suspension or termination of the entire program if operational damage occurs.
Priority Zero Rules
Please adhere to the following rules while performing research on this program:
- Denial of service (DoS) attacks on Alasco GmbH applications, servers, networks, or infrastructure are strictly forbidden.
- Tests that could cause degradation or interruption of our services are strictly forbidden.
- Do not use automated scanners or tools that generate large amounts of network traffic, or use them in a very gentle way (maximum 1 request per second unless explicitly permitted otherwise).
- Do not leak, manipulate, destroy, download, copy, or exfiltrate any user data, company data, or files from our applications, servers, or systems.
- Do not alter real data under any circumstances.
- No vulnerability disclosure, full, partial, or otherwise, is allowed without explicit written consent from Alasco.
- Do not spam registration forms or any public-facing forms on our websites, including but not limited to https://www.alasco.de/explore/
- You must append the defined user-agent to all web-based requests.
- Use dummy/test accounts and clearly identifiable test data whenever possible.
- If Alasco’s Security Team requests that you pause or stop testing, you must comply immediately.
- If you are unsure whether an action is safe, stop testing and ask first via the report discussion thread.
Target-specific Program Rules
In addition to the Priority Zero Rules above, the following target-specific rules apply where communicated for a given scope:
-
Test only during approved hours
Limit all testing activities to 08:00–17:00 CET. Do not perform any scans, automation, or manual testing outside this time window unless you have explicit written approval. -
Do not disrupt our business
Do not run automation, scans, or tests that could degrade performance, disrupt services, or impact real users. If your activity risks service stability, stop immediately. -
Avoid heavy automation
Do not run parallelized or high-volume automated tooling unless you have prior written approval. Default behaviour should be manual or single-threaded, low-rate testing. -
No public disclosure without explicit written consent
Do not share findings, screenshots, logs, or artifacts with third parties. Report exclusively through the designated vulnerability disclosure platform. Public disclosure of any vulnerability requires written consent from Alasco — no exceptions. -
No altering of real data
Never change, download, or exfiltrate company data — even if you gain access to any. -
Use identifiable test data
Use dummy/test accounts and data that can be distinguished from normal traffic and production data. -
Follow Security Team instructions immediately
If Alasco’s Security Team requests that you pause or stop testing, comply at once. Their direction takes precedence to protect users and operations. -
If in doubt — stop and ask
When unsure about impact, environment, or data, pause testing and ask in the report discussion thread before proceeding.
Reward Eligibility
We are happy to thank everyone who submits valid reports which help us improve the security of Alasco GmbH, however only those that meet the following eligibility requirements may receive a monetary reward:
- You must be the first reporter of a vulnerability.
- The same vulnerability in different scopes will only count as one vulnerability.
- The vulnerability must be a qualifying vulnerability.
- The report must contain the following elements:
- Clear textual description of the vulnerability, how it can be exploited, the security impact it has on the application, its users, and Alasco GmbH, and remediation advice on fixing the vulnerability.
- Proof of exploitation: screenshots demonstrating the exploit was performed, and showing the final impact.
- Complete steps with the necessary information to reproduce the exploit, including, if necessary, code snippets, payloads, commands, etc.
- You must not break any of the testing policy rules listed above.
- You must not be a former or current employee of Alasco GmbH or one of its contractors.
Reward Grid
Reward amounts are based on:
- Reward grid of the report's scope
- CVSS scoring and actual business impact of the vulnerability upon performing risk analysis
- Discretionary judgement of Alasco’s CISO
Reward
| Asset value | CVSS | CVSS | CVSS | CVSS |
|---|---|---|---|---|
| €50 | €200 | €600 | €1,000 | |
| €50 | €200 | €600 | €1,000 | |
| €50 | €200 | €600 | €1,000 |
Scopes
| Scope | Type | Asset value | Expand rewards grid |
|---|---|---|---|
app.alasco.de | Web application | ||
Low Medium High Critical | |||
api.alasco.de | API | ||
Low Medium High Critical | |||
*.alasco.de | Other | ||
Low Medium High Critical | |||
*.alasco.rocks | Other | ||
Low Medium High Critical | |||
Out of scopes
- All other domains or subdomains not listed in the above list of 'Scopes'.
- explore.alasco.com
- explore.alasco.de
- www.alasco.de
- www.alasco.com
- alasco.de
- alasco.com
- lp.alasco.de
- lp.alasco.com
- support.alasco.de
- support.alasco.com
- Please note that all non-authenticated areas of our systems are in scope for this program. This means that any vulnerability discovered in a system or service that does not require a login to access is eligible for a reward.
- However, any vulnerability discovered in a system or service that requires a login to access is outside the scope of this program.
- Alasco will not provide access credentials to any system, not for testing and also not for issue validation.
- Attention: Third-party managed infrastructure (e.g. HubSpot, Salesforce, or other SaaS platforms) where Alasco has no ability to remediate vulnerabilities at the infrastructure or platform level, regardless of the subdomain.
Vulnerability types
Qualifying vulnerabilities
- SQL Injection (SQLi)
- Cross-Site Scripting (XSS)
- Remote Code Execution (RCE)
- Insecure Direct Object Reference (IDOR)
- Horizontal and vertical privilege escalation
- Authentication bypass & broken authentication
- Business Logic Errors vulnerability with real security impact
- Local files access and manipulation (LFI, RFI, XXE, SSRF, XSPA)
- Cross-Origin Resource Sharing (CORS) with real security impact
- Cross-site Request Forgery (CSRF) with real security impact
Non-qualifying vulnerabilities
- Tabnabbing
- Missing cookie flags
- Content/Text injections
- Mixed content warnings
- Clickjacking/UI redressing
- Denial of Service (DoS) attacks
- Known CVEs without working PoC
- Open ports without real security impact
- Social engineering of staff or contractors
- Presence of autocomplete attribute on web forms
- Vulnerabilities affecting outdated browsers or platforms
- Self-XSS or XSS that cannot be used to impact other users
- Outdated libraries without a demonstrated security impact
- Any hypothetical flaw or best practices without exploitable PoC
- Expired certificate, best practices and other related issues for TLS/SSL certificates
- Unexploitable vulnerabilities (ex: XSS or Open Redirect in HTTP Host Header)
- Reports with attack scenarios requiring MITM or physical access to victim's device
- Missing security-related HTTP headers which do not lead directly to a vulnerability
- Unauthenticated / Logout / Login and other low-severity Cross-Site Request Forgery (CSRF)
- Invalid or missing SPF (Sender Policy Framework), DKIM, DMARC records
- Session expiration policies (no automatic logout, invalidation after a certain time or after a password change)
- Disclosure of information without direct security impact (e.g. stack traces, path disclosure, directory listings, software versions, IP disclosure, 3rd party secrets)
- CSV injection
- HTTP Strict Transport Security Header (HSTS)
- Subdomain takeover without a full working PoC
- Blind SSRF without direct impact (e.g. DNS pingback)
- Lack of rate-limiting, brute-forcing or captcha issues
- User enumeration (email, alias, GUID, phone number)
- Password requirements policies (length / complexity / reuse)
- Ability to spam users (email / SMS / direct messages flooding)
- Disclosed / misconfigured Google API key (including Google Maps)
- Recently disclosed 0-day vulnerabilities (less than 14 days since patch release)
- Password reset token leak on trusted third-party website via Referer header (eg Google Analytics, Facebook…)
- Open redirect - unless an additional security impact can be demonstrated
- Dynamic Client Registration (DCR) — Our MCP server intentionally supports OAuth Dynamic Client Registration (RFC 7591) for MCP client compatibility. DCR is publicly accessible by design. Registrations are constrained to supported public OAuth clients and validated redirect URI patterns. Findings that rely solely on the ability to register an OAuth client via /mcp/oauth/register are non-qualifying, as this endpoint is intentionally open. Reports must demonstrate a complete, exploitable attack chain beyond client registration itself.
Hunting requirements
Account access
Open to the public: no login required to access in-scope systems and services.
User agent
Please append to your user-agent header the following value: ' -BugBounty-alasco-gmbh-31337 '.
Hunters collaboration
When submitting new report, you can add up to 5 collaborators, and define the reward split ratio.
For more information, see help center.
Note: For reports that have already been rewarded, it is not possible to redistribute the rewards.