Communication about potential valnerabilities is always via mail to kalle.bracht@outlook.de (project owner).
Please do not report security vulnerabilities through public issues or any other public communication.
The mail subject line should be short and contain the project name (NoReel) and the type of vulnerability. The mail should contain:
- The type of issue (e.g., buffer overflow, SQL injection, or cross-site scripting)
- Affected version(s)
- Impact of the issue, including how an attacker might exploit the issue
- Step-by-step instructions to reproduce the issue
- The location of the affected source code (tag/branch/commit or direct URL)
- Full paths of source file(s) related to the manifestation of the issue
- Configuration required to reproduce the issue
- Log files that are related to this issue (if possible)
- Device information (e.g. Android build version) (if possible)
- Proof-of-concept or exploit code (if possible)
This information will help us triage your report more quickly.
If there are any open questions left behind, feel free to contact the mail address above.