mirror of
https://git.victorphan.net/basketballcantho/zalo-monitor.git
synced 2026-08-05 06:13:10 +07:00
2.2 KiB
2.2 KiB
name, about, title, labels, assignees
| name | about | title | labels | assignees |
|---|---|---|---|---|
| Security Vulnerability Report | Report a security vulnerability | [SECURITY] | security |
Security Vulnerability Report
IMPORTANT: This issue will be handled privately and with the highest priority. Please do not disclose details publicly until the issue is resolved.
Vulnerability Type
- Authentication bypass
- Data exposure/information disclosure
- Code injection
- Cross-site scripting (XSS)
- Cross-site request forgery (CSRF)
- Denial of service (DoS)
- Privilege escalation
- Dependency vulnerability
- Other (please describe)
Severity Level
- Critical (immediate action required)
- High (action required within 24 hours)
- Medium (action required within 1 week)
- Low (action required within 1 month)
Description
Steps to Reproduce
Expected Behavior
Actual Behavior
Environment
- zca-js Version:
- Node.js Version:
- Operating System:
- Browser (if applicable):
Impact Assessment
- Data at Risk:
- Users Affected:
- Business Impact:
Suggested Fix
Additional Information
Disclosure Timeline
Note: This report will be reviewed by the security team and handled according to our Security Policy. We appreciate your responsible disclosure and will work to resolve this issue promptly.
⚠️ Warning: This is an unofficial API library. Please ensure your testing does not violate Zalo's terms of service or put any accounts at risk.