BookBeat
Bounty Range
$50 - $2,000
external program
BountyHall of fame
€50 Low €100 Medium €300 High €1,000 Critical €2,000
Avg reward -
Max reward -
Scopes5
Supported languagesEnglish
BookBeat is a subscription service for audiobooks and eBooks.
Security is very important to us and this Bug Bounty program shall help us meet highest industry standards to offer the most secure service and experience to all parties.
Please adhere to the following rules while performing research on this program:
Make sure to apply hunting requirements policy, specifically User-Agent, so that our teams know the detected activity is related to this program. If not, you might be blocked from our assets due to our security protocols.
Denial of service (DoS) attacks on BookBeat applications, servers, networks or infrastructure are strictly forbidden.
Avoid tests that could cause degradation or interruption of our services.
Do not use automated scanners or tools that generate large amount of network traffic
Do not leak, copy, manipulate, or destroy any user data or files in any of our applications/servers.
No vulnerability disclosure, full, partial or otherwise, is allowed.
We are happy to thank everyone who submits valid reports which help us improve the security of BookBeat, however only those that meet the following eligibility requirements may receive a monetary reward:
You must be the first reporter of a vulnerability.
The vulnerability must be a qualifying vulnerability
The report must contain the following elements:
Clear textual description of the vulnerability, how it can be exploited, the security impact it has on the application, its users and BookBeat, and remediation advice on fixing the vulnerability
Proof of exploitation: screenshots demonstrating the exploit was performed, and showing the final impact
Provide complete steps with the necessary information to reproduce the exploit, including (if necessary) code snippets, payloads, commands etc
You must not break any of the testing policy rules listed above
You must not be a former or current employee of BookBeat or one of its contractors.
Reward amounts are based on:
Reward grid of the report's scope
CVSS scoring and actual business impact of the vulnerability upon performing risk analysis
Important information about the scope:
Asset value | CVSS Low | CVSS Medium | CVSS High | CVSS Critical | Medium | €100 | €300 | €1,000 | €2,000 |
1st report100% 2nd report100% 3rd report75% 4th report50% 5th report25% 6th+ report10%
In the context of this program, we do not intend to encourage, accept or reward reports of leaks that are not applicable to our program's scope and policy. To summarize our policy, you may refer to the below table:
| Scope | Type | Asset value |
|---|---|---|
| https://www.bookbeat.com | Web application | Medium |
| https://api.bookbeat.com | API | Medium |
| https://search-api.bookbeat.com | API | Medium |
| https://play.google.com/store/apps/details?id=com.bookbeat.android&hl=en&pli=1 | Mobile application Android | Medium |
| https://apps.apple.com/se/app/bookbeat-audiobooks-e-books/id1056652614?l=en-GB | Mobile application IOS | Medium |
Reward Grid for all scopes:
In the context of this program, we do not intend to encourage, accept or reward reports of leaks that are not applicable to our program's scope and policy. The following table summarizes this policy:
| Type of leak | Source of leak is in-scope | Source of leak belongs to the Organization and is out-of-scope | Source of leak does not belong to the Organization and is out-of-scope |
|---|---|---|---|
| Impact is in-scope (e.g. valid credentials on an in-scope asset) | Eligible | Eligible | Not eligible |
| Impact is out-of-scope (e.g. valid credentials for an out-of-scope asset) | Eligible | Not eligible | Not eligible |
For BookBeat scope testing, you can self-register wherever it is allowed. Please use your YesWeHack email aliases for account creation.
For API access, please use your own BookBeat account with the following headers:
Route: https://api.bookbeat.com/api/login
Please append to your user-agent header the following value: yeswehack
When submitting new report, you can add up to 5 collaborators, and define the reward split ratio. For more information, see the help center. Note: For reports that have already been rewarded, it is not possible to redistribute the rewards.