ISO Mate is grateful to the security researchers who take the time to responsibly report vulnerabilities to us. Their work helps us keep our platform and our customers safe. This page recognizes the people who have made a valued contribution to the security of ISO Mate.
A Note on Compensation
ISO Mate does not currently operate a guaranteed paid bug bounty program. As an early-stage company, we are not yet in a position to offer immediate monetary rewards for vulnerability reports, and we want to be completely transparent about this.
However, we deeply value the security community and do not want your hard work to go unappreciated. We carefully track all valid submissions. While future payouts cannot be legally guaranteed today, it is our earnest goal to recognize these early contributions retrospectively as our company grows. ISO Mate reserves the right to issue discretionary, retroactive rewards to eligible researchers when our financial position allows.
Being listed here in our Security Hall of Fame serves as a permanent record of your invaluable contribution to our security and our gratitude for your help.
Responsible Disclosure
We ask that researchers give us a reasonable opportunity to investigate and remediate a reported issue before disclosing it publicly. To protect our customers, we only add a researcher and the details of their finding to this page after the vulnerability has been fully remediated. Entries are published with the researcher’s permission, and we are happy to credit you by name, handle, or anonymously, whichever you prefer.
Safe Harbor and Scope
We want researchers to test with confidence. If you act in good faith and follow our disclosure policy, we consider your research authorized and will not pursue legal action against you. The policy also sets out which systems are in scope, which are out of scope, and the testing activities we do not permit. Please review it before you begin: Vulnerability Disclosure Policy.
Recognized Researchers
The researchers below have responsibly disclosed vulnerabilities that we have since remediated. We add new entries here as reports are validated and fixed, with each researcher’s permission.
| Forscher | Gemeldete Schwachstelle | Datum der Anerkennung |
|---|---|---|
| Omkar Dalavi | Zugriffstoken blieb nach der Abmeldung gültig | August 2026 |
| Jahidul Hasan Munna | Fehlerhafte Autorisierung auf Funktionsebene bei Dashboard-Endpunkten | August 2026 |
| Jahidul Hasan Munna | Fehlende Ratenbegrenzung bei der Datensatzerstellung ermöglicht Überflutung des Arbeitsbereichs | August 2026 |
| Swatantra Kokare | Fehlerhafte OAuth-Kontobindung nach einer Änderung der E-Mail-Adresse | August 2026 |
| Manas Pipersaniya (VIT Bhopal University) | Fehlende Sicherheitsheader bei statisch ausgelieferten Dateien | August 2026 |
| Aseeruddin Mulla | Fehlende Durchsetzung von Kontingenten auf Kontoebene ermöglicht unkontrollierte Benutzeranlage | August 2026 |
| Karan Patil | Gespeichertes Cross-Site-Scripting (XSS) in geteilten Notizen | August 2026 |
| Jebin Jose | Fehlender Selbsthilfeweg aus der Sperre wegen nicht verifizierter E-Mail | August 2026 |
| Vijay Raghav | Gespeicherte HTML-Injektion in Notizinhalten | August 2026 |
| Sahil More | Host-Header-Injection ermöglicht Weiterleitung auf eine beliebige Domain | August 2026 |
| Pramod Rathod | Aktive Sitzungen nach dem Zurücksetzen des Passworts nicht ungültig gemacht | August 2026 |
| Arjun Pandurang Tupe | Umgehung der E-Mail-Verifizierung über die Anmeldung mit Google | August 2026 |
| Pramod Rathod | Fehlende Validierung der Eingabelänge im Registrierungsformular | August 2026 |
| Umar (Stalker) | Fehlende Ratenbegrenzung bei Benutzereinladungen ermöglicht Missbrauch des ausgehenden E-Mail-Versands | August 2026 |
| Umar (Stalker) | Rechteausweitung in der Konto- und Rollenverwaltung | August 2026 |
| Umar (Stalker) | Unzureichende Rechteverwaltung bei Rollendelegation und Kontoinhaberschaft | August 2026 |
| Umar (Stalker) | Gespeichertes Cross-Site-Scripting (XSS) über Dateianhang-Upload | August 2026 |
| Anonym | Unbeschränkte Kalendererstellung ermöglicht Ressourcenerschöpfung | August 2026 |
| Mayuri S. Patwardhan | Fehlende Content-Security-Policy in der Anwendungskonsole | Juli 2026 |
| Mayuri S. Patwardhan | Content-Security-Policy, die Inline-Skripte zulässt | Juli 2026 |
| Mayuri S. Patwardhan | Cookie ohne SameSite-Attribut gesetzt | Juli 2026 |
| Mayuri S. Patwardhan | Veraltete X-XSS-Protection-Kopfzeile zurückgegeben | Juli 2026 |
| Mayuri S. Patwardhan | Fehlende Kopfzeilen zur Cross-Origin-Isolierung | Juli 2026 |
| Pathan Aslam | Spoofing von E-Mail-Adressen durch Unicode-Homoglyphen | Juli 2026 |
| Pathan Aslam | Gespeichertes Cross-Site-Scripting (XSS) über Logo-Upload | Juli 2026 |
| Pathan Aslam | Unzureichende Verifizierung bei der Änderung der Konto-E-Mail | Juli 2026 |
| Pathan Aslam | Aktive Sitzungen bei Passwortänderung nicht ungültig gemacht | Juli 2026 |
| Pathan Aslam | Fehlende Validierung der maximalen Passwortlänge | Juli 2026 |
| Pathan Aslam | Fehlende Benachrichtigungs-E-Mail bei Passwortänderung | Juli 2026 |
| Pathan Aslam | Fehlende erneute Authentifizierung bei sensiblen administrativen Aktionen (Benutzerlöschung) | Juli 2026 |
| Soham D. Jadhav | Gespeicherte Hyperlink-Injektion | Juli 2026 |
| Team TrinityXploit | Enumeration von Benutzernamen über Anmeldefehlermeldungen | Juli 2026 |
| Omkar Yepre | Details auf Wunsch des Forschers vertraulich behandelt | Juli 2026 |
| Team TrinityXploit | Vom Benutzer kontrollierte Links in Benachrichtigungs-E-Mails wiedergegeben | Juli 2026 |
| Kartik Kapil Lonkar | Unkontrollierter Ressourcenverbrauch über den Endpunkt für geplante Aufgaben | Juli 2026 |
| Sankalp Tripathi | Umgehung der Testbeschränkung über E-Mail-Adressen-Aliase | Juli 2026 |
| Vivek Rajendra Udane | Nicht validierte E-Mail-Empfängerdomains ermöglichen Missbrauch des ausgehenden E-Mail-Versands | Juli 2026 |
| Akif Ali Khan | Offenlegung der Webserver-Version über die Server-Kopfzeile | Juli 2026 |
| Anonym | Fehlende Durchsetzung von HTTP Strict Transport Security (HSTS) | Juni 2026 |
How to Report a Vulnerability
If you believe you have found a security vulnerability in ISO Mate, please email us at security@isomate.io with enough detail for us to reproduce and validate the issue. We will acknowledge your report, keep you informed as we investigate, and let you know once the issue is resolved. For the full rules of engagement, see our Vulnerability Disclosure Policy. For more information about how we protect your data, see our Security Practices page.
Contact
For anything related to security or responsible disclosure, please contact us at security@isomate.io.