Skip to content

Security: NETivism/netiCRM

Security Navigation

SECURITY.md

Security Policy

Please do not report security vulnerabilities through public GitHub issues.

Reporting a Vulnerability

Instead, please report them to our security report email address with subject "security advisory":

security-report (at) netivism.com.tw

You should receive a response within 24 hours. If for some reason you do not, please follow up via email to ensure we received your original message.

If you can provide any of this, it will help us better understand the nature and scope of the possible issue:

  • Type of issue (e.g. SQL injection, cross-site scripting, etc.)
  • Full paths of source file(s) related to the manifestation of the issue (which often copy of github url with line number)
  • The location of the affected source code (tag/branch/commit or direct URL)
  • Any special configuration required to reproduce the issue
  • Step-by-step instructions to reproduce the issue
  • Proof-of-concept or exploit code (if possible)
  • Impact of the issue, including how an attacker might exploit the issue

We take security of this project very seriously. Thank you for helping us better.