Reporting Cybersecurity Issue: UNESCO’s Responsible Disclosure policy
What to Report
Any digital security incidents or details of vulnerabilities associated with publicly accessible UNESCO information communications technology resources (ICT), including websites.
What not to report
Out of scope vulnerabilities include the following:
- ICT sites/web applications not under UNESCO.ORG domain.
- Any test not related to web sites or Web applications (no DNS or Email related configurations).
- Cookie Not Marked as HttpOnly.
- Cookie Not Marked as Secure.
- Missing HTTP security headers.
- HTTP Header Information Disclosure.
- Missing HTTP Strict Transport Security Policy.
- Software version disclosure/banner identification.
- Missing best practices in SSL/TLS configuration.
- xmlrpc.php with no admin page exposed to the Internet.
- No automated fuzzing of forms or web scraping type of activities.
- Any activity that could lead to the disruption of service (DoS).
However, if a critical issue is found concomitantly even if it is out of scope, please do report it.
Vulnerability Reporting Policy
UNESCO may accept disclosures of vulnerabilities under the following conditions:
- The vulnerability is related to UNESCO’s ICT resources.
- The vulnerability has not already been publicly disclosed.
- The vulnerability is reported to UNESCO as soon as possible after its discovery.
- The vulnerability findings must remain confidential for at least 90 days following the date the vulnerability was reported to the UNESCO or until public disclosure of the vulnerability has been made on this website.
- The severity of a vulnerability finding is assessed by the UNESCO at its own discretion.
- The name and contact information of the reporter may be disclosed to affected technology vendor(s), unless otherwise requested by the reporter.
UNESCO reserves the right to accept or reject any security vulnerability disclosure report at its discretion.
For reports concerning other UN resources and assets, please consult information on .
If more information is required regarding a reported vulnerability, the UNESCO Digital Security team may contact the reporter.
If UNESCO accepts the security vulnerability disclosure report, UNESCO will verify the existence of the vulnerability, notify affected parties, and implement actions to mitigate the vulnerability.
Once the vulnerability has been removed, the reporter will be acknowledged unless he/she wishes to remain anonymous, and listed on this page with a short description of the vulnerability reported.
By reporting vulnerability findings to UNESCO, the reporter acknowledges that such reporting is provided pro bono and without expectation of financial or other compensation.
The reporter also affirms that neither he/she nor any entity that he/she represents is complicit in human rights abuses, tolerates forced or compulsory labour or use child labour, is involved in the sale or manufacture of anti-personnel mines or their components, or does not comply with the purposes and principles of UNESCO.
How to report?
Researchers can report vulnerabilities via a PGP encrypted email to cybersecurity@unesco.org with a clear documentation on how to reproduce this reported vulnerability.
Hall of Fame
(mailto)
reported a XSS vulnerability on UNESCO resources
11 December 2024
reported a Arbitrary File Upload vulnerability on UNESCO resources
5 December 2024.
Chang LIU (mailto)
reported a SSRF vulnerability on UNESCO resources
3 December 2024
(mailto)
reported a Misconfigured FTP Server vulnerability on UNESCO resources
2 December 2024
陈岩&苍产蝉辫; (mailto)
reported a Reflective XSS vulnerability on UNESCO resources
28 November 2024
(mailto)
reported a Security Misconfiguration vulnerability on UNESCO resources
11 November 2024
Mahmoud Abouhalima (mailto)
reported a Subdomain takeover vulnerability on UNESCO resources
11 November 2024
Mahmoud Abouhalima (mailto)
reported a XSS vulnerability on UNESCO resources
11 November 2024
(mailto)
reported a Password Reset Logic Flaw vulnerability on UNESCO resources
9 November 2024
reported a HTMLi to XSS vulnerability on UNESCO resources
7 November 2024
(mailto)
reported a Clickjacking vulnerability on UNESCO resources
6 November 2024
(mailto)
reported a XSS vulnerability on UNESCO resources
2 November 2024
(mailto)
reported a Security Misconfiguration vulnerability on UNESCO resources
31 October 2024
(mailto)
reported a XSS vulnerability on UNESCO resources
30 October 2024
肖子龙 (mailto)
reported a XSS vulnerability on UNESCO resources
30 October 2024
(mailto)
reported a HTMLivulnerability on UNESCO resources
30 October 2024
(mailto)
reported a XSS vulnerability on UNESCO resources
29 October 2024
reported a SSH Channel Integrity Compromise vulnerability on UNESCO resources
29 October 2024
(mailto)
reported a Apache Tomcat Open Redirect vulnerability on UNESCO resources
21 October 2024
Kaliunisec
Reported a SQLi vulnerability on UNESCO resources
21 October 2024
reported a XSS vulnerability on UNESCO resources
21 October 2024
(mailto)
reported a Accessible Google Drive vulnerability on UNESCO resources:
19 October 2024
Reported a SQLi on UNESCO resources
12 December 2024
(mailto)
Reported a IIS Short Filename Disclosure on UNESCO resources
04 December 2024
(mailto)
Reported a IIS Short Filename Disclosure on UNESCO resources
04 December 2024
(mailto)
Reported a directory listing on UNESCO resources
03 December 2024
(mailto)
Reported a XSS on UNESCO resources
30 November 2024
Reported a Clickjacking on UNESCO resources
25 November 2024
Reported two xmlrpc.php misconfiguration on UNESCO resources
25 November 2024
(mailto)
Reported a XSS Clickjacking on UNESCO resources
23 November 2024
(mailto)
Reported a XSS (Swagger-UI) on UNESCO resources
21 November 2024
Reported a Configuration Exposure on UNESCO resources
20 November 2024
(mailto)
Reported a Exposed API Key on UNESCO resources
15 November 2024
Reported a security misconfiguration on UNESCO resources
13 November 2024
(mailto)
Reported a HTTP Methode Bypass on UNESCO resources
12 November 2024
Reported a Password Rate Limit on UNESCO resources
12 November 2024
Reported a HTMLi to XSS on UNESCO resources
09 November 2024
Reported a load-scripts.php on UNESCO resources
09 November 2024
Reported a Configuration File Exposure on UNESCO resources
09 November 2024
(mailto)
Reported a Long password denial of service on UNESCO resources
05 November 2024
(mailto)
Reported a Data Exposure on UNESCO resources
05 November 2024
Reported a No timeout on UNESCO resources
05 November 2024
(mailto)
Reported a Data Exposure on UNESCO resources
04 November 2024
Reported a HTMLi on UNESCO resources
01 November 2024
(mailto)
Reported a XSS on UNESCO resources
30 October 2024
(mailto)
Reported a XSS on UNESCO resources
30 October 2024
(mailto)
Reported a SQLi on UNESCO resources
30 October 2024
(mailto)
Reported a XSS on UNESCO resources
29 October 2024
(mailto)
Reported a HTMLi on UNESCO resources
29 October 2024
(mailto)
Reported a Server-Side Request Forgery on UNESCO resources
29 October 2024
Reported a XSS via Chatbot on UNESCO resources
03 October 2024
Reported a SQLi vulnerability on UNESCO resources
20 October 2024
Reported a SQLi vulnerability on UNESCO resources
15 October 2024
(mailto)
Reported a XSS on UNESCO resources
14 October 2024
(mailto)
Reported a HTMLi vulnerability on UNESCO resources
14 October 2024
(mailto)
Reported a two HTMLi vulnerabilities on UNESCO resources
14 October 2024
(mailto)
Reported an empty Placeholder on UNESCO resources
13 October 2024
(mailto)
Reported a HTMLi on UNESCO resources
10 October 2024
(mailto)
Reported a security misconfiguration on UNESCO resources
10 October 2024
(mailto)
Reported a Potential Subdomain Takeover on UNESCO resources
10 October 2024
(mailto)
Reported a Data Exposure vulnerability on UNESCO resources
10 October 2024
(mailto)
Reported a XSS vulnerability on UNESCO resources
07 October 2024
(mailto)
Reported 4 Configuration File Exposure on UNESCO resources
05 October 2024
(mailto)
Reported a XSS on UNESCO resources
03 October 2024
(mailto)
Reported Exposed data on UNESCO resources
30 September 2024
Linate 宋秉霖/HashRun&Cyb3rK1ng security team (mailto)
Reported a XSS vulnerability on UNESCO resources
29 September 2024
(mailto)
Reported a potential Subdomain Takeover on UNESCO resources
29 September 2024
(mailto)
Reported 7 Configuration File Exposure on UNESCO resources
27 September 2024
(mailto)
Reported a Arbitrary Text Injection vulnerability on UNESCO resources
27 September 2024
Reported a Prototype Pollution vulnerability on UNESCO resources
25 September 2024
Linate 宋秉霖/HashRun&Cyb3rK1ng security team (mailto)
Reported a Prototype Pollution vulnerability on UNESCO resources
25 September 2024
石丰瑞(mailto)
Reported a XSS vulnerability on UNESCO resources
25 September 2024
(mailto)
Reported a HTMLi vulnerability on UNESCO resources
25 September 2024
(mailto)
Reported Exposed Data on UNESCO resources
24 September 2024
(mailto)
Reported two no rate limit vulnerabilities on UNESCO resources
24 September 2024
(mailto)
Reported a 6 Configuration File Exposure on UNESCO resources
24 September 2024
(mailto)
Reported a Clickjacking vulnerability on UNESCO resources
23 September 2024
(mailto)
Reported a JavaScript Vulnerability on UNESCO resources
23 September 2024
(mailto)
Reported a no rate limit vulnerability on UNESCO resources
22 September 2024
(mailto)
Reported a XSS via Chatbot vulnerability on UNESCO resources
21 September 2024
(mailto)
Reported a HTMLi vulnerability on UNESCO resources
21 September 2024
(mailto)
Reported CSRF vulnerability on UNESCO resources
20 September 2024
(mailto)
Reported a No Rate Limit Vulnerability on UNESCO resources
20 September 2024
(mailto)
Reported a File Upload Vulnerability Leading on UNESCO resources
20 September 2024
Reported a open redirection vulnerability on UNESCO resources
19 September 2024
Reported a open redirection vulnerability on UNESCO resources
18 September 2024
Reported a open redirection vulnerability on UNESCO resources
17 September 2024
(mailto)
Reported a Data Exposure on UNESCO resources
17 September 2024
(mailto)
Reported a Broken Link Hijacking on UNESCO resources
16 September 2024
(mailto)
Reported a Configuration File Exposure on UNESCO resources
16 September 2024
Reported 3 XSS vulnerability on UNESCO resources
16 September 2024
(mailto)
Reported a HTMLi vulnerability on UNESCO resources
09 September 2024
(mailto)
Reported a XSS vulnerability on UNESCO resources
09 September 2024
(王磊)
Reported a XSS vulnerability on UNESCO resources
04 September 2024
Reported 2 configuration File Exposure on UNESCO resources
31 August 2024
(mailto)
Reported 2 configuration File Exposure on UNESCO resources
30 August 2024
Reported a XSS Vulnerability on UNESCO resources
30 August 2024
(mailto)
Reported a configuration File Exposure on UNESCO resources
29 August 2024
(mailto)
Reported a SQLi Vulnerability on UNESCO resources
26 August 2024
Reported 3 XSS vulnerabilities on UNESCO resources
26 August 2024
(mailto)
Reported a No Rate Limit Vulnerability on UNESCO resources
26 August 2024
(mailto)
Reported a open redirection vulnerability on UNESCO resources
23 August 2024
(mailto)
Reported a HTMLi vulnerability on UNESCO resources
20 August 2024
(mailto)
Reported a Cross-Origin Resource Sharing on UNESCO resources
11 August 2024
(mailto)
Reported a XSS vulnerability on UNESCO resources
09 August 2024
(mailto)
Reported a XSS vulnerability on UNESCO resources
31 July 2024
(mailto)
Reported a XML-RPC vulnerability on UNESCO resources
29 June 2024
(mailto)
Reported a IDOR & CSRF vulnerability on UNESCO resources
14 June 2024
Abhishrey Gupta / Crimson Inferno (mailto)
Reported a Clickjacking vulnerability on UNESCO resources
12 June 2024
Reported 33 security misconfigurations on UNESCO resources over the course of a month
3 September 2024
Reported 2 security misconfigurations on UNESCO resources
30 August 2024
Reported 2 security misconfigurations on UNESCO resources
28 August 2024
(mailto)
Reported a security misconfiguration on iiep.unesco.org
26 August 2024
(mailto)
Reported two security misconfiguration on UNESCO resources
24 August 2024
(mailto)
Reported a security misconfiguration on unesco.org
23 August 2024
(mailto)
Reported 2 security misconfigurations on UNESCO resources
22 August 2024
Reported a security misconfiguration on iiep.unesco.org
22 August 2024
(mailto)
Reported 5 security misconfigurations on UNESCO resources
21 August 2024
(mailto)
Reported 3 security misconfigurations on UNESCO resources
21 August 2024
(mailto)
Reported 2 security misconfigurations on UNESCO resources
21 August 2024
Reported 2 security misconfigurations on UNESCO resources
21 August 2024
Reported a security misconfiguration on unevoc.unesco.org
21 August 2024
(mailto)
Reported 7 security misconfigurations on UNESCO resources
20 August 2024
Reported a security misconfiguration on unesdoc.unesco.org
1 August 2024
(mailto)
Reported a security misconfiguration on uil.unesco.org
1 August 2024
(mailto)
Reported a security misconfiguration on unesco.org
16 July 2024
Reported a security misconfiguration on bangkok.unesco.org
7 July 2024
Reported 2 security misconfigurations on UNESCO resources
22 June 2024
(mailto)
Reported XSS Vulnerability on unevoc.unesco.org
13 June 2024
(mailto)
Reported 6 Clickjacking on several ressources
12 June 2024
(mailto)
Reported a PII on iieslac.unesco.org
6 May 2024
leeya_bug ()
Reported a security misconfiguration onunesco.org
2 April 2024
(mailto)
Reported SQLi Vulnerability on uis.unesco.org
1 April 2024
(mailto)
Reported XSS Vulnerability on whc.unesco.org
27 March 2024
(mailto)
Reported a XSS Vulnerability on iiep.unesco.org
26 March 2024
(mailto)
Reported XSS Vulnerability on unevoc.unesco.org
23 March 2024
(mailto)
Reported a security misconfiguration on ich.unesco.org
23 March 2024
Reported a security misconfiguration on iiep.unesco.org
28 February 2024
(mailto)
Reported XSS Vulnerability on whc.unesco.org
14 February 2024
(mailto)
Reported 3 security misconfiguration on unesco.org
6 February 2024
Reported a security misconfiguration on iesalc.unesco.org
18 January 2024
(mailto)
Reported a security misconfiguration on uis.unesco.org
2 January 2024
(mailto)
Reported a security misconfiguration on ich.unesco.org
24 July 2023