Signalement d¡¯un probl¨¨me de cybers¨¦curit¨¦ : Politique de divulgation des vuln¨¦rabilit¨¦s en mati¨¨re de s¨¦curit¨¦

L¡¯UNESCO est reconnaissante de l'aide apport¨¦e par le public pour renforcer la s¨¦curit¨¦ de ses ressources en mati¨¨re de technologies de l'information et de la communication, en informant l'UNESCO de toute faiblesse sur les syst¨¨mes d'information et les actifs que l'UNESCO met ¨¤ la disposition du public, ainsi qu'en signalant tous types de probl¨¨mes de cybers¨¦curit¨¦.
Derni¨¨re mise ¨¤ jour4 mars 2025

Quoi signaler

Tout incident de s¨¦curit¨¦ ou vuln¨¦rabilit¨¦ associ¨¦e aux ressources des technologies de l'information et de la communication (TIC) de l'UNESCO accessibles au public, y compris ses sites web.

Quoi ne pas signaler

Les vuln¨¦rabilit¨¦s hors du p¨¦rim¨¨tres sont les suivantes : 

  • TIC sites/web applications en dehors du domaine UNESCO.ORG 
  • Tous les tests sur des sites ou applications web non li¨¦es (pas de configuration DNS ou email associ¨¦ ¨¤ l¡¯UNESCO). 
  • Cookie non marqu¨¦ comme HttpOnly. 
  • Cookie non marqu¨¦ comme Secure. 
  • HTTP security headers manquant. 
  • HTTP Header Information Disclosure manquant. 
  • Divulgation de la version du logiciel/ banner identification. 
  • Meilleures pratiques manquantes dans la configuration SSL/TLS. 
  • xmlrpc.php sans page d'administration expos¨¦e ¨¤ Internet. 
  • Pas de fuzzing automatis¨¦ des formulaires ni d'activit¨¦s de type web scraping. 
  • Toute activit¨¦ pouvant conduire ¨¤ une interruption de service (DoS). 

Cependant, si un incident critique a ¨¦t¨¦ identifi¨¦ concomitamment, merci de le signaler

Politique de signalement des vuln¨¦rabilit¨¦s

L¡¯UNESCO peux prendre en compte les signalements de vuln¨¦rabilit¨¦s sur la base des conditions suivantes : 

  • La vuln¨¦rabilit¨¦ est li¨¦e ¨¤ une ressource TIC de l¡¯UNESCO. 
  • La vuln¨¦rabilit¨¦ n¡¯a pas d¨¦j¨¤ ¨¦t¨¦ publi¨¦e officiellement. 
  • La vuln¨¦rabilit¨¦ est signal¨¦e d¨¨s que possible ¨¤ l¡¯UNESCO apr¨¨s sa d¨¦couverte. 
  • La vuln¨¦rabilit¨¦ signal¨¦e et ses d¨¦tails doivent rester confidentiel pendant au moins 90 jours apr¨¨s la date du signalement aupr¨¨s de l¡¯UNESCO ou jusqu¡¯¨¤ sa divulgation au public sur ce site web. 
  • La criticit¨¦ de la vuln¨¦rabilit¨¦ est ¨¦valu¨¦e par l¡¯UNESCO ¨¤ sa discr¨¦tion. 
  • Le nom et les informations de contact de la personne ayant signal¨¦ la vuln¨¦rabilit¨¦ pourront ¨ºtre partag¨¦s avec le(s) fournisseur(s) de l¡¯application, sauf indication contraire du chercheur. 
  • UNESCO se r¨¦serve le droit de rejeter des signalements de vuln¨¦rabilit¨¦s ¨¤ sa discr¨¦tion. 

Pour signaler des vuln¨¦rabilit¨¦s concernant des ressources d¡¯autres organisation des Nations Unies, nous vous invitons ¨¤ vous r¨¦f¨¦rer ¨¤ .

L¡¯UNESCO contactera les chercheurs ¨¤ l¡¯origine du signalement si des d¨¦tails suppl¨¦mentaires sont n¨¦cessaires. Si l¡¯UNESCO prends en compte le rapport de signalement de la vuln¨¦rabiliti¨¦, l'UNESCO v¨¦rifiera l¡¯existence de la vuln¨¦rabilit¨¦, informera les parties prenantes, et impl¨¦mentera les actions pour mitiger la vuln¨¦rabilit¨¦. Une fois que la vuln¨¦rabilit¨¦ aura ¨¦t¨¦ corrig¨¦e, le chercheur sera remerci¨¦ sauf contre-indication de sa part, et list¨¦ sur cette page avec une description courte de la vuln¨¦rabilit¨¦ signal¨¦e. 

En signalant une vuln¨¦rabilit¨¦ ¨¤ l¡¯UNESCO, le chercheur reconnait que cette action est effectu¨¦e pro bono et sans contrepartie financi¨¨re ou d¡¯autre type. Le chercheur s¡¯engage ¨¤ ne pas ¨ºtre, ¨¤ titre personnel ou via son organisation, complice de crime contre l¡¯humanit¨¦, tol¨¨re le travail forc¨¦ ou le travail des enfants, est impliqu¨¦ dans la vente ou la fabrication de mines anti-personnelles ou leurs composants, ou ne respectent pas les principes et objectifs de l¡¯UNESCO.

Comment signaler?

Les chercheurs peuvent signaler une vuln¨¦rabilit¨¦ via un email chiffr¨¦ avec une cl¨¦ PGP ¨¤ cybersecurity@unesco.org contenant une documentation claire pr¨¦sentant comment reproduire la vuln¨¦rabilit¨¦ d¨¦crite. 

Hall of Fame

 (mailto

reported a XSS vulnerability on UNESCO resources

11 December 2024

reported a Arbitrary File Upload vulnerability on UNESCO resources

5 December 2024.

Chang LIU (mailto

reported a SSRF vulnerability on UNESCO resources

3 December 2024

(mailto

reported a Misconfigured FTP Server vulnerability on UNESCO resources

2 December 2024

³ÂÑÒ&²Ô²ú²õ±è; (mailto

reported a Reflective XSS vulnerability on UNESCO resources

28 November 2024

(mailto

reported a Security Misconfiguration vulnerability on UNESCO resources

11 November 2024

Mahmoud Abouhalima (mailto)

reported a Subdomain takeover vulnerability on UNESCO resources

11 November 2024

Mahmoud Abouhalima (mailto)

reported a XSS vulnerability on UNESCO resources

11 November 2024

(mailto

reported a Password Reset Logic Flaw vulnerability on UNESCO resources

9 November 2024

 

reported a HTMLi to XSS vulnerability on UNESCO resources

7 November 2024

 (mailto

reported a Clickjacking vulnerability on UNESCO resources 

6 November 2024

(mailto)

reported a XSS vulnerability on UNESCO resources

2 November 2024

(mailto

reported a Security Misconfiguration vulnerability on UNESCO resources

31 October 2024

(mailto

reported a XSS vulnerability on UNESCO resources

30 October 2024

Ф×ÓÁú (mailto)

reported a XSS vulnerability on UNESCO resources

30 October 2024

(mailto

reported a HTMLivulnerability on UNESCO resources

30 October 2024

(mailto

reported a XSS vulnerability on UNESCO resources

29 October 2024

reported a SSH Channel Integrity Compromise vulnerability on UNESCO resources

29 October 2024

(mailto

reported a Apache Tomcat Open Redirect vulnerability on UNESCO resources

21 October 2024

Kaliunisec

Reported a SQLi vulnerability on UNESCO resources

21 October 2024

reported a XSS vulnerability on UNESCO resources

21 October 2024

(mailto

reported a Accessible Google Drive vulnerability on UNESCO resources: 

19 October 2024

 

Reported a SQLi on UNESCO resources

12 December 2024

(mailto)

Reported a IIS Short Filename Disclosure on UNESCO resources

04 December 2024

(mailto)

Reported a IIS Short Filename Disclosure on UNESCO resources

04 December 2024

(mailto)

Reported a directory listing on UNESCO resources

03 December 2024

(mailto)

Reported a XSS on UNESCO resources

30 November 2024

(mailto

Reported a Clickjacking on UNESCO resources

25 November 2024

Reported two xmlrpc.php misconfiguration on UNESCO resources

25 November 2024

(mailto)

Reported a XSS Clickjacking on UNESCO resources

23 November 2024

(mailto)

Reported a XSS (Swagger-UI) on UNESCO resources

21 November 2024

Reported a Configuration Exposure on UNESCO resources

20 November 2024

(mailto)

Reported a Exposed API Key on UNESCO resources

15 November 2024

Reported a security misconfiguration on UNESCO resources

13 November 2024

(mailto)

Reported a HTTP Methode Bypass on UNESCO resources

12 November 2024

Reported a Password Rate Limit on UNESCO resources

12 November 2024

Reported a HTMLi to XSS on UNESCO resources

09 November 2024

Reported a load-scripts.php on UNESCO resources

09 November 2024

Reported a Configuration File Exposure on UNESCO resources

09 November 2024

(mailto)

Reported a Long password denial of service on UNESCO resources

05 November 2024

(mailto)

Reported a Data Exposure on UNESCO resources

05 November 2024

Reported a No timeout on UNESCO resources

05 November 2024

(mailto)

Reported a Data Exposure on UNESCO resources

04 November 2024

Reported a HTMLi on UNESCO resources

01 November 2024

(mailto)

Reported a XSS on UNESCO resources

30 October 2024

(mailto)

Reported a XSS on UNESCO resources

30 October 2024

(mailto)

Reported a SQLi on UNESCO resources

30 October 2024

(mailto)

Reported a XSS on UNESCO resources

29 October 2024

(mailto)

Reported a HTMLi on UNESCO resources

29 October 2024

(mailto)

Reported a Server-Side Request Forgery on UNESCO resources

29 October 2024

Reported a XSS via Chatbot on UNESCO resources

03 October 2024

 

Reported a SQLi vulnerability on UNESCO resources  

20 October 2024 

 

Reported a SQLi vulnerability on UNESCO resources  

15 October 2024

(mailto)

Reported a XSS on UNESCO resources  

14 October 2024

(mailto

Reported a HTMLi vulnerability on UNESCO resources  

14 October 2024

 (mailto

Reported a two HTMLi vulnerabilities on UNESCO resources

14 October 2024 

 (mailto

Reported an empty Placeholder on UNESCO resources  

13 October 2024 

 (mailto

Reported a HTMLi on UNESCO resources  

10 October 2024 

 (mailto)

Reported a security misconfiguration on UNESCO resources  

10 October 2024 

 (mailto

Reported a Potential Subdomain Takeover on UNESCO resources

10 October 2024 

 (mailto

Reported a Data Exposure vulnerability on UNESCO resources  

10 October 2024 

 (mailto

Reported a XSS vulnerability on UNESCO resources  

07 October 2024

 (mailto

Reported 4 Configuration File Exposure on UNESCO resources

05 October 2024 

 (mailto

Reported a XSS on UNESCO resources  

03 October 2024

 (mailto

Reported Exposed data on UNESCO resources  

30 September 2024 

Linate ËαüÁØ/HashRun&Cyb3rK1ng security team (mailto

Reported a XSS vulnerability on UNESCO resources

29 September 2024

 (mailto

Reported a potential Subdomain Takeover on UNESCO resources

29 September 2024 

 (mailto

Reported 7 Configuration File Exposure on UNESCO resources 

27 September 2024

(mailto

Reported a Arbitrary Text Injection vulnerability on UNESCO resources  

27 September 2024 

 

Reported a Prototype Pollution vulnerability on UNESCO resources 

25 September 2024 

Linate ËαüÁØ/HashRun&Cyb3rK1ng security team (mailto

Reported a Prototype Pollution vulnerability on UNESCO resources 

25 September 2024

ʯ·áÈð(mailto

Reported a XSS vulnerability on UNESCO resources 

25 September 2024 

 (mailto

Reported a HTMLi vulnerability on UNESCO resources  

25 September 2024

 (mailto

Reported Exposed Data on UNESCO resources  

24 September 2024

 (mailto

Reported two no rate limit vulnerabilities on UNESCO resources 

24 September 2024 

 (mailto

Reported a 6 Configuration File Exposure on UNESCO resources 

24 September 2024

(mailto

Reported a Clickjacking vulnerability on UNESCO resources

23 September 2024 

 (mailto

Reported a JavaScript Vulnerability on UNESCO resources  

23 September 2024 

 (mailto

Reported a no rate limit vulnerability on UNESCO resources

22 September 2024

 (mailto

Reported a XSS via Chatbot vulnerability on UNESCO resources  

21 September 2024 

(mailto

Reported a HTMLi vulnerability on UNESCO resources  

21 September 2024 

 (mailto

Reported CSRF vulnerability on UNESCO resources

20 September 2024 

 (mailto

Reported a No Rate Limit Vulnerability on UNESCO resources

20 September 2024 

 (mailto

Reported a File Upload Vulnerability Leading on UNESCO resources  

20 September 2024

Reported a open redirection vulnerability on UNESCO resources

19 September 2024

Reported a open redirection vulnerability on UNESCO resources  

18 September 2024 

 

Reported a open redirection vulnerability on UNESCO resources 

17 September 2024 

 (mailto

Reported a Data Exposure on UNESCO resources  

17 September 2024 

 (mailto

Reported a Broken Link Hijacking on UNESCO resources  

16 September 2024 

(mailto

Reported a Configuration File Exposure on UNESCO resources

16 September 2024 

 

Reported 3 XSS vulnerability on UNESCO resources

16 September 2024

 (mailto

Reported a HTMLi vulnerability on UNESCO resources

09 September 2024

 (mailto

Reported a XSS vulnerability on UNESCO resources  

09 September 2024

(ÍõÀÚ)

Reported a XSS vulnerability on UNESCO resources  

04 September 2024

 

Reported 2 configuration File Exposure on UNESCO resources 

31 August 2024

 (mailto

Reported 2 configuration File Exposure on UNESCO resources 

30 August 2024

 

Reported a XSS Vulnerability on UNESCO resources  

30 August 2024 

 (mailto

Reported a configuration File Exposure on UNESCO resources 

29 August 2024 

 (mailto

Reported a SQLi Vulnerability on UNESCO resources  

26 August 2024 

 

Reported 3 XSS vulnerabilities on UNESCO resources  

26 August 2024 

 (mailto

Reported a No Rate Limit Vulnerability on UNESCO resources  

26 August 2024 

(mailto)

Reported a open redirection vulnerability on UNESCO resources  

23 August 2024

  (mailto

Reported a HTMLi vulnerability on UNESCO resources  

20 August 2024 

 (mailto)

 Reported a Cross-Origin Resource Sharing on UNESCO resources 

11 August 2024

 (mailto)

Reported a XSS vulnerability on UNESCO resources  

09 August 2024 

(mailto

Reported a XSS vulnerability on UNESCO resources  

31 July 2024 

 (mailto

Reported a XML-RPC vulnerability on UNESCO resources  

29 June 2024 

 (mailto

Reported a IDOR & CSRF vulnerability on UNESCO resources  

14 June 2024

Abhishrey Gupta / Crimson Inferno (mailto

Reported a Clickjacking vulnerability on UNESCO resources  

12 June 2024 

Reported 33 security misconfigurations on UNESCO resources over the course of a month

3 September 2024

Reported 2 security misconfigurations on UNESCO resources

30 August 2024

Reported 2 security misconfigurations on UNESCO resources

28 August 2024

(mailto)

Reported a security misconfiguration on iiep.unesco.org

26 August 2024

(mailto)

Reported two security misconfiguration on UNESCO resources

24 August 2024

(mailto)

Reported a security misconfiguration on unesco.org

23 August 2024

(mailto)

Reported 2 security misconfigurations on UNESCO resources

22 August 2024

Reported a security misconfiguration on iiep.unesco.org

22 August 2024

(mailto)

Reported 5 security misconfigurations on UNESCO resources

21 August 2024

(mailto)

Reported 3 security misconfigurations on UNESCO resources

21 August 2024

(mailto)

Reported 2 security misconfigurations on UNESCO resources

21 August 2024

Reported 2 security misconfigurations on UNESCO resources

21 August 2024

Reported a security misconfiguration on unevoc.unesco.org

21 August 2024

(mailto)

Reported 7 security misconfigurations on UNESCO resources

20 August 2024

Reported a security misconfiguration on unesdoc.unesco.org

1 August 2024

(mailto)

Reported a security misconfiguration on uil.unesco.org

1 August 2024

(mailto)

Reported a security misconfiguration on unesco.org

16 July 2024

Reported a security misconfiguration on bangkok.unesco.org

7 July 2024

Reported 2 security misconfigurations on UNESCO resources

22 June 2024

(mailto)

Reported XSS Vulnerability on unevoc.unesco.org

13 June 2024

(mailto)

Reported 6 Clickjacking on several ressources

12 June 2024

(mailto)

Reported a PII on iieslac.unesco.org

6 May 2024

leeya_bug ()

Reported a security misconfiguration onunesco.org

2 April 2024

(mailto)

Reported SQLi Vulnerability on uis.unesco.org

1 April 2024

(mailto)

Reported XSS Vulnerability on whc.unesco.org

27 March 2024

(mailto)

Reported a XSS Vulnerability on iiep.unesco.org

26 March 2024

(mailto)

Reported XSS Vulnerability on unevoc.unesco.org

23 March 2024

(mailto)

Reported a security misconfiguration on ich.unesco.org

23 March 2024

Reported a security misconfiguration on iiep.unesco.org

28 February 2024

(mailto)

Reported XSS Vulnerability on whc.unesco.org

14 February 2024

(mailto)

Reported 3 security misconfiguration on unesco.org

6 February 2024

Reported a security misconfiguration on iesalc.unesco.org

18 January 2024

(mailto)

Reported a security misconfiguration on uis.unesco.org

2 January 2024

(mailto)

Reported a security misconfiguration on ich.unesco.org

24 July 2023