Responsible disclosure
Report safely
Report suspected public-site vulnerabilities with enough detail to reproduce the issue. Do not access, modify, delete, exfiltrate, or disrupt data or systems.
Include
- Affected URL.
- Steps to reproduce.
- Expected and observed behavior.
- Potential impact.
- Safe proof of concept.
Do not perform
- Destructive testing.
- Social engineering.
- Credential attacks.
- Data exfiltration.
- Testing outside public site authorization.