Security Policy

Reporting a vulnerability

The security of the modules we develop for the PrestaShop marketplace is paramount. This is why we encourage security researchers to carry out analyses on our modules and to report any identified vulnerability to us, in compliance with responsible disclosure best practices.

We are committed to identifying and fixing any vulnerability, and to communicating transparently with the parties concerned throughout the process.

If you believe you have discovered a vulnerability in one of our modules, you can report it to us responsibly at the following address: site@loulou66.fr

We invite you to provide us with as much detail as possible (description, impact, affected version, reproduction steps).

Please note that non-reproducible findings or those not directly related to our modules are ignored.

Our vulnerability management policy

In accordance with the TouchWeb Charter for responsible cybersecurity, our team applies the following principles:

  • Acknowledgement of receipt of any relevant report within a maximum of 7 days (CVSS ≥ 7.5).
  • Impact analysis and planning of a fix within a maximum of 30 days.
  • Publication of a security advisory with a CVE if the CVSS score is ≥ 7.5.
  • No fix will be released silently.

In addition, we make the following commitments to ensure responsible and ethical vulnerability management:

  • Not to prosecute researchers acting in good faith, in particular within the framework of the YesWeHack program managed by TouchWeb SAS.
  • To ensure that no confidentiality agreement, including white-label ones, can hinder the transparent publication of a security advisory with a CVE identifier, in accordance with the state of the art.

We are fully aware that this transparency is essential to enable the third parties concerned (agencies, merchants, etc.) to meet their compliance obligations, in particular within the framework of the PCI-DSS standard or one of its lighter versions, such as SAQ-A.

Publication authorization

We expressly authorize the company TouchWeb SAS to publish information relating to the fixed vulnerabilities of our modules on its official website, in accordance with the commitments of the Responsible cybersecurity charter.

This publication includes:

  • A CVE identifier associated with the vulnerability.
  • A security note clearly describing the issue and its resolution.
  • The affected versions and the fixed version.
  • An easy-to-deploy fix when updating is not possible.
  • Any useful information enabling users and agencies to protect themselves quickly.
Responsible Cybersecurity Badge — TouchWeb Charter

Publications

No publication to date.