Vulnerability disclosure program

LiveAgent aims to keep its service safe for everyone, and data security is of utmost importance. Our Vulnerability Disclosure Program is intended to minimize the impact any security flaws have on our tools or their users. LiveAgent’s Vulnerability Disclosure Program covers software partially or primarily written by Quality Unit.

If you are a security researcher and have discovered a security vulnerability in the Service, we appreciate your help in disclosing it to us privately and giving us an opportunity to fix it before publishing technical details.

LiveAgent will engage with security researchers when vulnerabilities are reported to us as described here. We will validate, respond, and fix vulnerabilities in support of our commitment to security and privacy. We won’t take legal action against, suspend, or terminate access to the Service of those who discover and report security vulnerabilities responsibly. LiveAgent reserves all of its legal rights in the event of any noncompliance.

Reporting

Share the details of any suspected vulnerabilities with the LiveAgent Development Team at support@liveagent.com. Please do not publicly disclose these details outside of this process without explicit permission. In reporting any suspected vulnerabilities, please include as much information as possible. If you want to submit multiple reports at once, please submit only one report (the most important if possible) and wait for a response.

Compensation

We are pleased to offer a bounty for vulnerability information that helps us protect our customers as a thanks to the security researchers who choose to participate in our bug bounty program. The regular bounty reward is $100 per vulnerability submitted and verified by our development team.

We will only reward the first reporter of a vulnerability. Duplicate reports will not be rewarded.

Scope

You may only test against a LiveAgent Account for which you are the Account Owner or an Agent authorized by the Account Owner to conduct such testing. For example:

  • *yourdomain*.ladesk.com

We will reward you for the following types of vulnerabilities:

  • Remote Command Execution (RCE)
  • SQL Injection
  • Broken Authentication
  • Broken Session Management
  • Access Control Bypass
  • Cross-Site Scripting (XSS)
  • Cross-Site Request Forgery (CSRF)
  • Open URL Redirection
  • Directory Traversal

Reports of when an attacker can only threaten his own account with Admin role only will not be rewarded with a bounty. XSS caused by an Admin will not be rewarded with a bounty.

In order to qualify, the vulnerability must exist in the latest public release (including officially released public betas) of the software. Only security vulnerabilities will qualify. We would love it if people reported other bugs via the appropriate channels, but since the purpose of this program is to fix security vulnerabilities, only bugs that lead to security vulnerabilities will be eligible for rewards. Other bugs will be accepted at our discretion.

Guidelines

Please adhere to the following guidelines in order to be eligible for rewards under this disclosure program:

  • Do not permanently modify or delete LiveAgent hosted data.
  • Do not intentionally access non-public LiveAgent data any more than is necessary to demonstrate the vulnerability.
  • Do not DDoS or otherwise disrupt, interrupt or degrade our internal or external services.
  • Do not share confidential information obtained from LiveAgent, including but not limited to member or donor payment information, with any third party.
  • Social engineering is out of scope. Do not send phishing emails to, or use other social engineering techniques against, anyone, including QualityUnit staff, members, vendors, or partners.

In addition, please allow us at least 90 days to fix the vulnerability before publicly discussing or blogging about it. Our team believes that security researchers have right to report their research and that disclosure is highly beneficial, and understands that it is a highly subjective question of when and how to hold back details to mitigate the risk that vulnerability information will be misused. If you believe that earlier disclosure is necessary, please let us know so that we can begin a conversation.

Change log

We publicly inform about all fixed security issues through our change log. Issues related to security are marked by tag [Security].

Related Articles

LiveAgent support portal

LiveAgent is a customer support software with a variety of features, including ticketing, live chat, social helpdesk, and voice helpdesk. The software is accessible from anywhere and has SSL safety. Users can access technical support, video tutorials, customizations, billing, and payments support, and awards and certificates. The platform offers most popular articles and integrates with Rest and Microsoft 365, among others. Helpdesk software is provided by LiveAgent and all rights are reserved to Quality Unit, LLC.

Sorry, I am not able to generate a summary for the given text as I am not able to read the text.

liveagent

Sorry, I am not able to generate a summary for the given text as I am not able to read the text.

LiveAgent fits the needs of entertainment industry by offering live chat functionalities in order to provide fast online help.

Helpdesk software for Entertainment industry

An entertainment company can benefit from customer service software, which can manage interactions, streamline activities, and increase engagement. LiveAgent is a recommended helpdesk solution, offering email, chat, social media, and forum inquiries in one platform, creating an efficient agent workflow. LiveAgent offers multiple benefits, such as improving customer retention, satisfaction, revenue, and reducing costs. LiveAgent also offers a free trial and no setup fees, with customer service available 24/7.

Are you looking for a feature-rich help desk solution? LiveAgent is a help desk software with more than 180 features available.

Features

LiveAgent is a versatile customer service software that offers a range of features including ticketing system, multiple customer portals, knowledge base, search widgets, mobile help desk apps, cryptography and multiple data centres. Password validators, SSO and billing management are also available. Moreover, LiveAgent integrates with various other platforms such as Slack, WordPress, Drupal and SquareSpace. Other services include CTI, CRM, eCommerce and email marketing. Migration plugins are also available to import data from previous help desk systems.

Our website uses cookies. By continuing we assume your permission to deploy cookies as detailed in our privacy and cookies policy.

Start Free Trial x