Vulnerability Detection

Vulnerability Detection Policy

If you have information related to security vulnerabilities of TalentLMS, we want to hear from you. Please submit a report in accordance with the guidelines below. We value the positive impact of your work and thank you in advance for your contribution.

We will offer a reward of up to $100, depending on severity, to people who submit vulnerability detection reports that adhere to the guidelines and scope defined below in this page and are assessed to be valid by the TalentLMS security team.

Guidelines

Epignosis agrees to not pursue claims against researchers related to the disclosures submitted through this website who:

  • do not cause harm to Epignosis, our customers, or others;

  • provide a detailed summary of the vulnerability, including the target, steps, tools, and artifacts used during discovery (the detailed summary will allow us to reproduce the vulnerability);

  • do not compromise the privacy or safety of our customers and the operation of our services;

  • do not violate any law or regulation;

  • publicly disclose vulnerability details only after Epignosis confirms completed remediation of the vulnerability and not publicly disclose vulnerability details if there is no completion date or completion cannot be ascertained;

  • confirm that they are not currently located in or otherwise ordinarily resident in Cuba, Iran, North Korea, Syria or Crimea; and

  • confirm that they are not on the U.S. Department of the Treasury’s Specially Designated Nationals List.

Out of Scope

  1. Reports from automated tools or scans
  2. Issues without clearly identified security impact (such as clickjacking on a static website), missing security headers, or descriptive error messages
  3. Missing best practices, information disclosures, use of known-vulnerable libraries or descriptive / verbose / unique error pages (without substantive information indicating exploitability)
  4. Speculative reports about theoretical damage without concrete evidence or some substantive information indicating exploitability
  5. Forms missing CSRF tokens without evidence of the actual CSRF vulnerability
  6. Self-exploitation (e.g., cookie reuse)
  7. Reports of insecure SSL / TLS ciphers (unless you have a working proof of concept, and not just a report from a scanner such as SSL Labs)
  8. Password complexity requirements, account/e-mail enumeration, or any report that discusses how you can learn whether a given username or email address has an Epignosis-related account
  9. Missing security-related HTTP headers which do not lead directly to a vulnerability
  10. Cross-site Scripting vulnerabilities without evidence on how the vulnerability can be used to attack another user
  11. Social engineering of Epignosis employees or contractors
  12. Presence of autocomplete attribute on web forms
  13. Missing secure cookie flags on non-sensitive cookies
  14. Denial of Service Attacks
  15. Banner identification issues (e.g., identifying what web server version is used)
  16. Open ports which do not lead directly to a vulnerability
  17. Open redirect vulnerabilities
  18. Publicly accessible login panels
  19. Clickjacking
  20. Content spoofing / text injection
  21. Tabnabbing
  22. Rate-limit vulnerabilities

In order to submit your vulnerability findings report, please contact us at security at talentlms.com. By contacting us, you consent to your information being transferred to and stored in the United States and acknowledge that you have read and accepted the Terms of Use and Privacy policy of TalentLMS.