Security

Security

Security

Webswing is committed to ensuring customer satisfaction achieved mainly by offering high- quality services, information security, preventing security issues, securing data, and maintaining continuity in case of a major issue.

In order to protect our customer base and the wide range of users, Webswing is committed to taking action to resolve any vulnerabilities in Webswing technology.


Contact our Security Team

We encourage you to report any potential vulnerability related to Webswing technology directly at security@webswing.org.

This email is reserved exclusively for reporting purposes only. It is not intended for any technical and/or licensing information.

Upon receiving your email, you will receive an automatic confirmation. Webswing is committed to verifying such reports and finding a solution in a reasonable amount of time. In this regard, we might ask for more information.

To ensure confidentiality, we encourage you to encrypt any sensitive information you send to us via email. We are equipped to receive messages encrypted using S/MIME. You can download a copy of the certificate in order to send us encrypted emails.


Webswing security information

Webswing distributes technical security information about its technology in the following ways:


  1. Via official webpage: https://www.webswing.org/security
  2. Via Webswing Client Portal: https://portal.webswing.org
  3. Security updates subscription

Webswing is willing to keep its customer base informed about the vulnerabilities that have been fixed for the respective version of Webswing technology, therefore, there will be a list of such vulnerabilities published according to points 1 and 2 above. If the person reporting the security issue is Webswing's customer, such customer will be informed by email within the time in accordance with the respective SLA.

Every Webswing user registered on the Client portal can also subscribe to receive alerts about security updates.

Any security issue will be published once the vulnerability is identified and fixed.

DateSeverityReferenceDescription
2022-07-08MediumCVE-2022-34914Allows X-Forwarded-For header injection.
2020-12-30CriticalCVE-2020-11103JSLink allows remote code execution
2024-04-17LowCVE-2023-45260XSS vulnerability in Webswing Admin console