Vulnerability Disclosure Policy
How to report security vulnerabilities responsibly
Contact
If you discover a security vulnerability in filemanager.bd, please report it responsibly by emailing:
We also publish a machine-readable security.txt (RFC 9116).
Scope
In scope:
filemanager.bdand all subdomains- The file manager web application and its API
- Authentication / session management
- File upload / download handling
- SFTP / SSH terminal functionality
Out of scope:
- Denial-of-service attacks
- Social engineering of staff
- Physical security
- Vulnerabilities in third-party services (bKash, Nagad, SSLCommerz, Cloudflare)
Our Commitments
- We will acknowledge receipt of your report within 3 business days.
- We will keep you informed of remediation progress.
- We will not pursue legal action against researchers acting in good faith.
- We will credit you in our release notes if you wish.
What to Include
- A clear description of the vulnerability
- Steps to reproduce (proof-of-concept preferred)
- Potential impact assessment
- Any suggested mitigations (optional)
Please allow up to 90 days for remediation before public disclosure.