Signalement d¡¯un probl¨¨me de cybers¨¦curit¨¦ : Politique de divulgation des vuln¨¦rabilit¨¦s en mati¨¨re de s¨¦curit¨¦
Quoi signaler
Tout incident de s¨¦curit¨¦ ou vuln¨¦rabilit¨¦ associ¨¦e aux ressources des technologies de l'information et de la communication (TIC) de l'UNESCO accessibles au public, y compris ses sites web.
Quoi ne pas signaler
Les vuln¨¦rabilit¨¦s hors du p¨¦rim¨¨tres sont les suivantes :
- TIC sites/web applications en dehors du domaine UNESCO.ORG
- Tous les tests sur des sites ou applications web non li¨¦es (pas de configuration DNS ou email associ¨¦ ¨¤ l¡¯UNESCO).
- Cookie non marqu¨¦ comme HttpOnly.
- Cookie non marqu¨¦ comme Secure.
- HTTP security headers manquant.
- HTTP Header Information Disclosure manquant.
- Divulgation de la version du logiciel/ banner identification.
- Meilleures pratiques manquantes dans la configuration SSL/TLS.
- xmlrpc.php sans page d'administration expos¨¦e ¨¤ Internet.
- Pas de fuzzing automatis¨¦ des formulaires ni d'activit¨¦s de type web scraping.
- Toute activit¨¦ pouvant conduire ¨¤ une interruption de service (DoS).
Cependant, si un incident critique a ¨¦t¨¦ identifi¨¦ concomitamment, merci de le signaler
Politique de signalement des vuln¨¦rabilit¨¦s
L¡¯UNESCO peux prendre en compte les signalements de vuln¨¦rabilit¨¦s sur la base des conditions suivantes :
- La vuln¨¦rabilit¨¦ est li¨¦e ¨¤ une ressource TIC de l¡¯UNESCO.
- La vuln¨¦rabilit¨¦ n¡¯a pas d¨¦j¨¤ ¨¦t¨¦ publi¨¦e officiellement.
- La vuln¨¦rabilit¨¦ est signal¨¦e d¨¨s que possible ¨¤ l¡¯UNESCO apr¨¨s sa d¨¦couverte.
- La vuln¨¦rabilit¨¦ signal¨¦e et ses d¨¦tails doivent rester confidentiel pendant au moins 90 jours apr¨¨s la date du signalement aupr¨¨s de l¡¯UNESCO ou jusqu¡¯¨¤ sa divulgation au public sur ce site web.
- La criticit¨¦ de la vuln¨¦rabilit¨¦ est ¨¦valu¨¦e par l¡¯UNESCO ¨¤ sa discr¨¦tion.
- Le nom et les informations de contact de la personne ayant signal¨¦ la vuln¨¦rabilit¨¦ pourront ¨ºtre partag¨¦s avec le(s) fournisseur(s) de l¡¯application, sauf indication contraire du chercheur.
- UNESCO se r¨¦serve le droit de rejeter des signalements de vuln¨¦rabilit¨¦s ¨¤ sa discr¨¦tion.
Pour signaler des vuln¨¦rabilit¨¦s concernant des ressources d¡¯autres organisation des Nations Unies, nous vous invitons ¨¤ vous r¨¦f¨¦rer ¨¤ .
L¡¯UNESCO contactera les chercheurs ¨¤ l¡¯origine du signalement si des d¨¦tails suppl¨¦mentaires sont n¨¦cessaires. Si l¡¯UNESCO prends en compte le rapport de signalement de la vuln¨¦rabiliti¨¦, l'UNESCO v¨¦rifiera l¡¯existence de la vuln¨¦rabilit¨¦, informera les parties prenantes, et impl¨¦mentera les actions pour mitiger la vuln¨¦rabilit¨¦. Une fois que la vuln¨¦rabilit¨¦ aura ¨¦t¨¦ corrig¨¦e, le chercheur sera remerci¨¦ sauf contre-indication de sa part, et list¨¦ sur cette page avec une description courte de la vuln¨¦rabilit¨¦ signal¨¦e.
En signalant une vuln¨¦rabilit¨¦ ¨¤ l¡¯UNESCO, le chercheur reconnait que cette action est effectu¨¦e pro bono et sans contrepartie financi¨¨re ou d¡¯autre type. Le chercheur s¡¯engage ¨¤ ne pas ¨ºtre, ¨¤ titre personnel ou via son organisation, complice de crime contre l¡¯humanit¨¦, tol¨¨re le travail forc¨¦ ou le travail des enfants, est impliqu¨¦ dans la vente ou la fabrication de mines anti-personnelles ou leurs composants, ou ne respectent pas les principes et objectifs de l¡¯UNESCO.
Hall of Fame
(mailto)
reported a XSS vulnerability on UNESCO resources
11 December 2024
reported a Arbitrary File Upload vulnerability on UNESCO resources
5 December 2024.
Chang LIU (mailto)
reported a SSRF vulnerability on UNESCO resources
3 December 2024
(mailto)
reported a Misconfigured FTP Server vulnerability on UNESCO resources
2 December 2024
³ÂÑÒ&²Ô²ú²õ±è; (mailto)
reported a Reflective XSS vulnerability on UNESCO resources
28 November 2024
(mailto)
reported a Security Misconfiguration vulnerability on UNESCO resources
11 November 2024
Mahmoud Abouhalima (mailto)
reported a Subdomain takeover vulnerability on UNESCO resources
11 November 2024
Mahmoud Abouhalima (mailto)
reported a XSS vulnerability on UNESCO resources
11 November 2024
(mailto)
reported a Password Reset Logic Flaw vulnerability on UNESCO resources
9 November 2024
reported a HTMLi to XSS vulnerability on UNESCO resources
7 November 2024
(mailto)
reported a Clickjacking vulnerability on UNESCO resources
6 November 2024
(mailto)
reported a XSS vulnerability on UNESCO resources
2 November 2024
(mailto)
reported a Security Misconfiguration vulnerability on UNESCO resources
31 October 2024
(mailto)
reported a XSS vulnerability on UNESCO resources
30 October 2024
Ф×ÓÁú (mailto)
reported a XSS vulnerability on UNESCO resources
30 October 2024
(mailto)
reported a HTMLivulnerability on UNESCO resources
30 October 2024
(mailto)
reported a XSS vulnerability on UNESCO resources
29 October 2024
reported a SSH Channel Integrity Compromise vulnerability on UNESCO resources
29 October 2024
(mailto)
reported a Apache Tomcat Open Redirect vulnerability on UNESCO resources
21 October 2024
Kaliunisec
Reported a SQLi vulnerability on UNESCO resources
21 October 2024
reported a XSS vulnerability on UNESCO resources
21 October 2024
(mailto)
reported a Accessible Google Drive vulnerability on UNESCO resources:
19 October 2024
Reported a SQLi on UNESCO resources
12 December 2024
(mailto)
Reported a IIS Short Filename Disclosure on UNESCO resources
04 December 2024
(mailto)
Reported a IIS Short Filename Disclosure on UNESCO resources
04 December 2024
(mailto)
Reported a directory listing on UNESCO resources
03 December 2024
(mailto)
Reported a XSS on UNESCO resources
30 November 2024
Reported a Clickjacking on UNESCO resources
25 November 2024
Reported two xmlrpc.php misconfiguration on UNESCO resources
25 November 2024
(mailto)
Reported a XSS Clickjacking on UNESCO resources
23 November 2024
(mailto)
Reported a XSS (Swagger-UI) on UNESCO resources
21 November 2024
Reported a Configuration Exposure on UNESCO resources
20 November 2024
(mailto)
Reported a Exposed API Key on UNESCO resources
15 November 2024
Reported a security misconfiguration on UNESCO resources
13 November 2024
(mailto)
Reported a HTTP Methode Bypass on UNESCO resources
12 November 2024
Reported a Password Rate Limit on UNESCO resources
12 November 2024
Reported a HTMLi to XSS on UNESCO resources
09 November 2024
Reported a load-scripts.php on UNESCO resources
09 November 2024
Reported a Configuration File Exposure on UNESCO resources
09 November 2024
(mailto)
Reported a Long password denial of service on UNESCO resources
05 November 2024
(mailto)
Reported a Data Exposure on UNESCO resources
05 November 2024
Reported a No timeout on UNESCO resources
05 November 2024
(mailto)
Reported a Data Exposure on UNESCO resources
04 November 2024
Reported a HTMLi on UNESCO resources
01 November 2024
(mailto)
Reported a XSS on UNESCO resources
30 October 2024
(mailto)
Reported a XSS on UNESCO resources
30 October 2024
(mailto)
Reported a SQLi on UNESCO resources
30 October 2024
(mailto)
Reported a XSS on UNESCO resources
29 October 2024
(mailto)
Reported a HTMLi on UNESCO resources
29 October 2024
(mailto)
Reported a Server-Side Request Forgery on UNESCO resources
29 October 2024
Reported a XSS via Chatbot on UNESCO resources
03 October 2024
Reported a SQLi vulnerability on UNESCO resources
20 October 2024
Reported a SQLi vulnerability on UNESCO resources
15 October 2024
(mailto)
Reported a XSS on UNESCO resources
14 October 2024
(mailto)
Reported a HTMLi vulnerability on UNESCO resources
14 October 2024
(mailto)
Reported a two HTMLi vulnerabilities on UNESCO resources
14 October 2024
(mailto)
Reported an empty Placeholder on UNESCO resources
13 October 2024
(mailto)
Reported a HTMLi on UNESCO resources
10 October 2024
(mailto)
Reported a security misconfiguration on UNESCO resources
10 October 2024
(mailto)
Reported a Potential Subdomain Takeover on UNESCO resources
10 October 2024
(mailto)
Reported a Data Exposure vulnerability on UNESCO resources
10 October 2024
(mailto)
Reported a XSS vulnerability on UNESCO resources
07 October 2024
(mailto)
Reported 4 Configuration File Exposure on UNESCO resources
05 October 2024
(mailto)
Reported a XSS on UNESCO resources
03 October 2024
(mailto)
Reported Exposed data on UNESCO resources
30 September 2024
Linate ËαüÁØ/HashRun&Cyb3rK1ng security team (mailto)
Reported a XSS vulnerability on UNESCO resources
29 September 2024
(mailto)
Reported a potential Subdomain Takeover on UNESCO resources
29 September 2024
(mailto)
Reported 7 Configuration File Exposure on UNESCO resources
27 September 2024
(mailto)
Reported a Arbitrary Text Injection vulnerability on UNESCO resources
27 September 2024
Reported a Prototype Pollution vulnerability on UNESCO resources
25 September 2024
Linate ËαüÁØ/HashRun&Cyb3rK1ng security team (mailto)
Reported a Prototype Pollution vulnerability on UNESCO resources
25 September 2024
ʯ·áÈð(mailto)
Reported a XSS vulnerability on UNESCO resources
25 September 2024
(mailto)
Reported a HTMLi vulnerability on UNESCO resources
25 September 2024
(mailto)
Reported Exposed Data on UNESCO resources
24 September 2024
(mailto)
Reported two no rate limit vulnerabilities on UNESCO resources
24 September 2024
(mailto)
Reported a 6 Configuration File Exposure on UNESCO resources
24 September 2024
(mailto)
Reported a Clickjacking vulnerability on UNESCO resources
23 September 2024
(mailto)
Reported a JavaScript Vulnerability on UNESCO resources
23 September 2024
(mailto)
Reported a no rate limit vulnerability on UNESCO resources
22 September 2024
(mailto)
Reported a XSS via Chatbot vulnerability on UNESCO resources
21 September 2024
(mailto)
Reported a HTMLi vulnerability on UNESCO resources
21 September 2024
(mailto)
Reported CSRF vulnerability on UNESCO resources
20 September 2024
(mailto)
Reported a No Rate Limit Vulnerability on UNESCO resources
20 September 2024
(mailto)
Reported a File Upload Vulnerability Leading on UNESCO resources
20 September 2024
Reported a open redirection vulnerability on UNESCO resources
19 September 2024
Reported a open redirection vulnerability on UNESCO resources
18 September 2024
Reported a open redirection vulnerability on UNESCO resources
17 September 2024
(mailto)
Reported a Data Exposure on UNESCO resources
17 September 2024
(mailto)
Reported a Broken Link Hijacking on UNESCO resources
16 September 2024
(mailto)
Reported a Configuration File Exposure on UNESCO resources
16 September 2024
Reported 3 XSS vulnerability on UNESCO resources
16 September 2024
(mailto)
Reported a HTMLi vulnerability on UNESCO resources
09 September 2024
(mailto)
Reported a XSS vulnerability on UNESCO resources
09 September 2024
(ÍõÀÚ)
Reported a XSS vulnerability on UNESCO resources
04 September 2024
Reported 2 configuration File Exposure on UNESCO resources
31 August 2024
(mailto)
Reported 2 configuration File Exposure on UNESCO resources
30 August 2024
Reported a XSS Vulnerability on UNESCO resources
30 August 2024
(mailto)
Reported a configuration File Exposure on UNESCO resources
29 August 2024
(mailto)
Reported a SQLi Vulnerability on UNESCO resources
26 August 2024
Reported 3 XSS vulnerabilities on UNESCO resources
26 August 2024
(mailto)
Reported a No Rate Limit Vulnerability on UNESCO resources
26 August 2024
(mailto)
Reported a open redirection vulnerability on UNESCO resources
23 August 2024
(mailto)
Reported a HTMLi vulnerability on UNESCO resources
20 August 2024
(mailto)
Reported a Cross-Origin Resource Sharing on UNESCO resources
11 August 2024
(mailto)
Reported a XSS vulnerability on UNESCO resources
09 August 2024
(mailto)
Reported a XSS vulnerability on UNESCO resources
31 July 2024
(mailto)
Reported a XML-RPC vulnerability on UNESCO resources
29 June 2024
(mailto)
Reported a IDOR & CSRF vulnerability on UNESCO resources
14 June 2024
Abhishrey Gupta / Crimson Inferno (mailto)
Reported a Clickjacking vulnerability on UNESCO resources
12 June 2024
Reported 33 security misconfigurations on UNESCO resources over the course of a month
3 September 2024
Reported 2 security misconfigurations on UNESCO resources
30 August 2024
Reported 2 security misconfigurations on UNESCO resources
28 August 2024
(mailto)
Reported a security misconfiguration on iiep.unesco.org
26 August 2024
(mailto)
Reported two security misconfiguration on UNESCO resources
24 August 2024
(mailto)
Reported a security misconfiguration on unesco.org
23 August 2024
(mailto)
Reported 2 security misconfigurations on UNESCO resources
22 August 2024
Reported a security misconfiguration on iiep.unesco.org
22 August 2024
(mailto)
Reported 5 security misconfigurations on UNESCO resources
21 August 2024
(mailto)
Reported 3 security misconfigurations on UNESCO resources
21 August 2024
(mailto)
Reported 2 security misconfigurations on UNESCO resources
21 August 2024
Reported 2 security misconfigurations on UNESCO resources
21 August 2024
Reported a security misconfiguration on unevoc.unesco.org
21 August 2024
(mailto)
Reported 7 security misconfigurations on UNESCO resources
20 August 2024
Reported a security misconfiguration on unesdoc.unesco.org
1 August 2024
(mailto)
Reported a security misconfiguration on uil.unesco.org
1 August 2024
(mailto)
Reported a security misconfiguration on unesco.org
16 July 2024
Reported a security misconfiguration on bangkok.unesco.org
7 July 2024
Reported 2 security misconfigurations on UNESCO resources
22 June 2024
(mailto)
Reported XSS Vulnerability on unevoc.unesco.org
13 June 2024
(mailto)
Reported 6 Clickjacking on several ressources
12 June 2024
(mailto)
Reported a PII on iieslac.unesco.org
6 May 2024
leeya_bug ()
Reported a security misconfiguration onunesco.org
2 April 2024
(mailto)
Reported SQLi Vulnerability on uis.unesco.org
1 April 2024
(mailto)
Reported XSS Vulnerability on whc.unesco.org
27 March 2024
(mailto)
Reported a XSS Vulnerability on iiep.unesco.org
26 March 2024
(mailto)
Reported XSS Vulnerability on unevoc.unesco.org
23 March 2024
(mailto)
Reported a security misconfiguration on ich.unesco.org
23 March 2024
Reported a security misconfiguration on iiep.unesco.org
28 February 2024
(mailto)
Reported XSS Vulnerability on whc.unesco.org
14 February 2024
(mailto)
Reported 3 security misconfiguration on unesco.org
6 February 2024
Reported a security misconfiguration on iesalc.unesco.org
18 January 2024
(mailto)
Reported a security misconfiguration on uis.unesco.org
2 January 2024
(mailto)
Reported a security misconfiguration on ich.unesco.org
24 July 2023
Comment signaler?
Les chercheurs peuvent signaler une vuln¨¦rabilit¨¦ via un email chiffr¨¦ avec une cl¨¦ PGP ¨¤ cybersecurity@unesco.org contenant une documentation claire pr¨¦sentant comment reproduire la vuln¨¦rabilit¨¦ d¨¦crite.