Reporting Cybersecurity Issue: UNESCO’s Responsible Disclosure policy

UNESCO welcomes the public's help in enhancing the security of its Information Communications Technology resources, by informing UNESCO of any weaknesses in the information system and assets that UNESCO makes available to the public, as well as by sharing any cybersecurity issues.
Last update:7 January 2025

What to Report

Any digital security incidents or details of vulnerabilities associated with publicly accessible UNESCO information communications technology resources (ICT), including websites.

What not to report

Out of scope vulnerabilities include the following:

  • ICT sites/web applications not under UNESCO.ORG domain. 
  • Any test not related to web sites or Web applications (no DNS or Email related configurations). 
  • Cookie Not Marked as HttpOnly. 
  • Cookie Not Marked as Secure. 
  • Missing HTTP security headers. 
  • HTTP Header Information Disclosure. 
  • Missing HTTP Strict Transport Security Policy. 
  • Software version disclosure/banner identification. 
  • Missing best practices in SSL/TLS configuration. 
  • xmlrpc.php with no admin page exposed to the Internet. 
  • No automated fuzzing of forms or web scraping type of activities. 
  • Any activity that could lead to the disruption of service (DoS). 

However, if a critical issue is found concomitantly even if it is out of scope, please do report it. 

Vulnerability Reporting Policy

UNESCO may accept disclosures of vulnerabilities under the following conditions:

  • The vulnerability is related to UNESCO’s ICT resources.
  • The vulnerability has not already been publicly disclosed.
  • The vulnerability is reported to UNESCO as soon as possible after its discovery.
  • The vulnerability findings must remain confidential for at least 90 days following the date the vulnerability was reported to the UNESCO or until public disclosure of the vulnerability has been made on this website.
  • The severity of a vulnerability finding is assessed by the UNESCO at its own discretion.
  • The name and contact information of the reporter may be disclosed to affected technology vendor(s), unless otherwise requested by the reporter.

UNESCO reserves the right to accept or reject any security vulnerability disclosure report at its discretion.

For reports concerning other UN resources and assets, please consult information on .

If more information is required regarding a reported vulnerability, the UNESCO Digital Security team may contact the reporter.

If UNESCO accepts the security vulnerability disclosure report, UNESCO will verify the existence of the vulnerability, notify affected parties, and implement actions to mitigate the vulnerability.

Once the vulnerability has been removed, the reporter will be acknowledged unless he/she wishes to remain anonymous, and listed on this page with a short description of the vulnerability reported.

By reporting vulnerability findings to UNESCO, the reporter acknowledges that such reporting is provided pro bono and without expectation of financial or other compensation. 

The reporter also affirms that neither he/she nor any entity that he/she represents is complicit in human rights abuses, tolerates forced or compulsory labour or use child labour, is involved in the sale or manufacture of anti-personnel mines or their components, or does not comply with the purposes and principles of UNESCO. 

How to report?

Researchers can report vulnerabilities via a PGP encrypted email to cybersecurity@unesco.org with a clear documentation on how to reproduce this reported vulnerability. 

Hall of Fame

 (mailto

reported a XSS vulnerability on UNESCO resources

11 December 2024

reported a Arbitrary File Upload vulnerability on UNESCO resources

5 December 2024.

Chang LIU (mailto

reported a SSRF vulnerability on UNESCO resources

3 December 2024

(mailto

reported a Misconfigured FTP Server vulnerability on UNESCO resources

2 December 2024

陈岩&苍产蝉辫; (mailto

reported a Reflective XSS vulnerability on UNESCO resources

28 November 2024

(mailto

reported a Security Misconfiguration vulnerability on UNESCO resources

11 November 2024

Mahmoud Abouhalima (mailto)

reported a Subdomain takeover vulnerability on UNESCO resources

11 November 2024

Mahmoud Abouhalima (mailto)

reported a XSS vulnerability on UNESCO resources

11 November 2024

(mailto

reported a Password Reset Logic Flaw vulnerability on UNESCO resources

9 November 2024

 

reported a HTMLi to XSS vulnerability on UNESCO resources

7 November 2024

 (mailto

reported a Clickjacking vulnerability on UNESCO resources 

6 November 2024

(mailto)

reported a XSS vulnerability on UNESCO resources

2 November 2024

(mailto

reported a Security Misconfiguration vulnerability on UNESCO resources

31 October 2024

(mailto

reported a XSS vulnerability on UNESCO resources

30 October 2024

肖子龙 (mailto)

reported a XSS vulnerability on UNESCO resources

30 October 2024

(mailto

reported a HTMLivulnerability on UNESCO resources

30 October 2024

(mailto

reported a XSS vulnerability on UNESCO resources

29 October 2024

reported a SSH Channel Integrity Compromise vulnerability on UNESCO resources

29 October 2024

(mailto

reported a Apache Tomcat Open Redirect vulnerability on UNESCO resources

21 October 2024

Kaliunisec

Reported a SQLi vulnerability on UNESCO resources

21 October 2024

reported a XSS vulnerability on UNESCO resources

21 October 2024

(mailto

reported a Accessible Google Drive vulnerability on UNESCO resources: 

19 October 2024

 

Reported a SQLi on UNESCO resources

12 December 2024

(mailto)

Reported a IIS Short Filename Disclosure on UNESCO resources

04 December 2024

(mailto)

Reported a IIS Short Filename Disclosure on UNESCO resources

04 December 2024

(mailto)

Reported a directory listing on UNESCO resources

03 December 2024

(mailto)

Reported a XSS on UNESCO resources

30 November 2024

(mailto

Reported a Clickjacking on UNESCO resources

25 November 2024

Reported two xmlrpc.php misconfiguration on UNESCO resources

25 November 2024

(mailto)

Reported a XSS Clickjacking on UNESCO resources

23 November 2024

(mailto)

Reported a XSS (Swagger-UI) on UNESCO resources

21 November 2024

Reported a Configuration Exposure on UNESCO resources

20 November 2024

(mailto)

Reported a Exposed API Key on UNESCO resources

15 November 2024

Reported a security misconfiguration on UNESCO resources

13 November 2024

(mailto)

Reported a HTTP Methode Bypass on UNESCO resources

12 November 2024

Reported a Password Rate Limit on UNESCO resources

12 November 2024

Reported a HTMLi to XSS on UNESCO resources

09 November 2024

Reported a load-scripts.php on UNESCO resources

09 November 2024

Reported a Configuration File Exposure on UNESCO resources

09 November 2024

(mailto)

Reported a Long password denial of service on UNESCO resources

05 November 2024

(mailto)

Reported a Data Exposure on UNESCO resources

05 November 2024

Reported a No timeout on UNESCO resources

05 November 2024

(mailto)

Reported a Data Exposure on UNESCO resources

04 November 2024

Reported a HTMLi on UNESCO resources

01 November 2024

(mailto)

Reported a XSS on UNESCO resources

30 October 2024

(mailto)

Reported a XSS on UNESCO resources

30 October 2024

(mailto)

Reported a SQLi on UNESCO resources

30 October 2024

(mailto)

Reported a XSS on UNESCO resources

29 October 2024

(mailto)

Reported a HTMLi on UNESCO resources

29 October 2024

(mailto)

Reported a Server-Side Request Forgery on UNESCO resources

29 October 2024

Reported a XSS via Chatbot on UNESCO resources

03 October 2024

 

Reported a SQLi vulnerability on UNESCO resources  

20 October 2024 

 

Reported a SQLi vulnerability on UNESCO resources  

15 October 2024

(mailto)

Reported a XSS on UNESCO resources  

14 October 2024

(mailto

Reported a HTMLi vulnerability on UNESCO resources  

14 October 2024

 (mailto

Reported a two HTMLi vulnerabilities on UNESCO resources

14 October 2024 

 (mailto

Reported an empty Placeholder on UNESCO resources  

13 October 2024 

 (mailto

Reported a HTMLi on UNESCO resources  

10 October 2024 

 (mailto)

Reported a security misconfiguration on UNESCO resources  

10 October 2024 

 (mailto

Reported a Potential Subdomain Takeover on UNESCO resources

10 October 2024 

 (mailto

Reported a Data Exposure vulnerability on UNESCO resources  

10 October 2024 

 (mailto

Reported a XSS vulnerability on UNESCO resources  

07 October 2024

 (mailto

Reported 4 Configuration File Exposure on UNESCO resources

05 October 2024 

 (mailto

Reported a XSS on UNESCO resources  

03 October 2024

 (mailto

Reported Exposed data on UNESCO resources  

30 September 2024 

Linate 宋秉霖/HashRun&Cyb3rK1ng security team (mailto

Reported a XSS vulnerability on UNESCO resources

29 September 2024

 (mailto

Reported a potential Subdomain Takeover on UNESCO resources

29 September 2024 

 (mailto

Reported 7 Configuration File Exposure on UNESCO resources 

27 September 2024

(mailto

Reported a Arbitrary Text Injection vulnerability on UNESCO resources  

27 September 2024 

 

Reported a Prototype Pollution vulnerability on UNESCO resources 

25 September 2024 

Linate 宋秉霖/HashRun&Cyb3rK1ng security team (mailto

Reported a Prototype Pollution vulnerability on UNESCO resources 

25 September 2024

石丰瑞(mailto

Reported a XSS vulnerability on UNESCO resources 

25 September 2024 

 (mailto

Reported a HTMLi vulnerability on UNESCO resources  

25 September 2024

 (mailto

Reported Exposed Data on UNESCO resources  

24 September 2024

 (mailto

Reported two no rate limit vulnerabilities on UNESCO resources 

24 September 2024 

 (mailto

Reported a 6 Configuration File Exposure on UNESCO resources 

24 September 2024

(mailto

Reported a Clickjacking vulnerability on UNESCO resources

23 September 2024 

 (mailto

Reported a JavaScript Vulnerability on UNESCO resources  

23 September 2024 

 (mailto

Reported a no rate limit vulnerability on UNESCO resources

22 September 2024

 (mailto

Reported a XSS via Chatbot vulnerability on UNESCO resources  

21 September 2024 

(mailto

Reported a HTMLi vulnerability on UNESCO resources  

21 September 2024 

 (mailto

Reported CSRF vulnerability on UNESCO resources

20 September 2024 

 (mailto

Reported a No Rate Limit Vulnerability on UNESCO resources

20 September 2024 

 (mailto

Reported a File Upload Vulnerability Leading on UNESCO resources  

20 September 2024

Reported a open redirection vulnerability on UNESCO resources

19 September 2024

Reported a open redirection vulnerability on UNESCO resources  

18 September 2024 

 

Reported a open redirection vulnerability on UNESCO resources 

17 September 2024 

 (mailto

Reported a Data Exposure on UNESCO resources  

17 September 2024 

 (mailto

Reported a Broken Link Hijacking on UNESCO resources  

16 September 2024 

(mailto

Reported a Configuration File Exposure on UNESCO resources

16 September 2024 

 

Reported 3 XSS vulnerability on UNESCO resources

16 September 2024

 (mailto

Reported a HTMLi vulnerability on UNESCO resources

09 September 2024

 (mailto

Reported a XSS vulnerability on UNESCO resources  

09 September 2024

(王磊)

Reported a XSS vulnerability on UNESCO resources  

04 September 2024

 

Reported 2 configuration File Exposure on UNESCO resources 

31 August 2024

 (mailto

Reported 2 configuration File Exposure on UNESCO resources 

30 August 2024

 

Reported a XSS Vulnerability on UNESCO resources  

30 August 2024 

 (mailto

Reported a configuration File Exposure on UNESCO resources 

29 August 2024 

 (mailto

Reported a SQLi Vulnerability on UNESCO resources  

26 August 2024 

 

Reported 3 XSS vulnerabilities on UNESCO resources  

26 August 2024 

 (mailto

Reported a No Rate Limit Vulnerability on UNESCO resources  

26 August 2024 

(mailto)

Reported a open redirection vulnerability on UNESCO resources  

23 August 2024

  (mailto

Reported a HTMLi vulnerability on UNESCO resources  

20 August 2024 

 (mailto)

 Reported a Cross-Origin Resource Sharing on UNESCO resources 

11 August 2024

 (mailto)

Reported a XSS vulnerability on UNESCO resources  

09 August 2024 

(mailto

Reported a XSS vulnerability on UNESCO resources  

31 July 2024 

 (mailto

Reported a XML-RPC vulnerability on UNESCO resources  

29 June 2024 

 (mailto

Reported a IDOR & CSRF vulnerability on UNESCO resources  

14 June 2024

Abhishrey Gupta / Crimson Inferno (mailto

Reported a Clickjacking vulnerability on UNESCO resources  

12 June 2024 

Reported 33 security misconfigurations on UNESCO resources over the course of a month

3 September 2024

Reported 2 security misconfigurations on UNESCO resources

30 August 2024

Reported 2 security misconfigurations on UNESCO resources

28 August 2024

(mailto)

Reported a security misconfiguration on iiep.unesco.org

26 August 2024

(mailto)

Reported two security misconfiguration on UNESCO resources

24 August 2024

(mailto)

Reported a security misconfiguration on unesco.org

23 August 2024

(mailto)

Reported 2 security misconfigurations on UNESCO resources

22 August 2024

Reported a security misconfiguration on iiep.unesco.org

22 August 2024

(mailto)

Reported 5 security misconfigurations on UNESCO resources

21 August 2024

(mailto)

Reported 3 security misconfigurations on UNESCO resources

21 August 2024

(mailto)

Reported 2 security misconfigurations on UNESCO resources

21 August 2024

Reported 2 security misconfigurations on UNESCO resources

21 August 2024

Reported a security misconfiguration on unevoc.unesco.org

21 August 2024

(mailto)

Reported 7 security misconfigurations on UNESCO resources

20 August 2024

Reported a security misconfiguration on unesdoc.unesco.org

1 August 2024

(mailto)

Reported a security misconfiguration on uil.unesco.org

1 August 2024

(mailto)

Reported a security misconfiguration on unesco.org

16 July 2024

Reported a security misconfiguration on bangkok.unesco.org

7 July 2024

Reported 2 security misconfigurations on UNESCO resources

22 June 2024

(mailto)

Reported XSS Vulnerability on unevoc.unesco.org

13 June 2024

(mailto)

Reported 6 Clickjacking on several ressources

12 June 2024

(mailto)

Reported a PII on iieslac.unesco.org

6 May 2024

leeya_bug ()

Reported a security misconfiguration onunesco.org

2 April 2024

(mailto)

Reported SQLi Vulnerability on uis.unesco.org

1 April 2024

(mailto)

Reported XSS Vulnerability on whc.unesco.org

27 March 2024

(mailto)

Reported a XSS Vulnerability on iiep.unesco.org

26 March 2024

(mailto)

Reported XSS Vulnerability on unevoc.unesco.org

23 March 2024

(mailto)

Reported a security misconfiguration on ich.unesco.org

23 March 2024

Reported a security misconfiguration on iiep.unesco.org

28 February 2024

(mailto)

Reported XSS Vulnerability on whc.unesco.org

14 February 2024

(mailto)

Reported 3 security misconfiguration on unesco.org

6 February 2024

Reported a security misconfiguration on iesalc.unesco.org

18 January 2024

(mailto)

Reported a security misconfiguration on uis.unesco.org

2 January 2024

(mailto)

Reported a security misconfiguration on ich.unesco.org

24 July 2023