Vulnerabilities found in ClickControl should be reported privately via email to contact@fodsoft.com.
Please do not open a GitHub issue to report a security vulnerability.
When reporting a vulnerability, please adhere to the following guidelines where possible:
- Verify Status: Check if the vulnerability has already been resolved in the latest release.
- Specify Version: Indicate the exact version of ClickControl in which the issue was discovered.
- Document the Issue: Provide detailed documentation, including replication steps or a proof of concept.
Confirmed security vulnerabilities will be addressed as a priority. Please note that ClickControl is managed by a solo maintainer; all reports are thoroughly reviewed, but individual email replies will not be sent. Thank you for your understanding and for helping keep the project secure.