Vulnerability Management: Reporting Security Vulnerabilities

Villanova University’s Vulnerability Disclosure Policy encourages individuals and organizations to responsibly and privately report potential security vulnerabilities affecting University systems and services. Information Security works proactively to prevent security problems and relies on reports from the University community and external researchers to help identify and address vulnerabilities. When a report is received, Information Security will acknowledge receipt when contact information is provided, assess the issue, and coordinate follow-up and remediation as appropriate, in accordance with the University’s Security Incident Response procedures. The preferred reporting method is to submit details through the Report a Security Vulnerability form or by sending an email to informationsecurity@villanova.edu.

Scope and Responsible Research

This policy covers reporting potential vulnerabilities affecting systems and services owned or operated by Villanova University. Reports involving third-party services used by the University are also welcome, however, Villanova cannot authorize testing of systems owned or operated by another organization.

This policy invites vulnerability reports but does not, by itself, authorize security testing. Contact Information Security before conducting testing to confirm scope and obtain any necessary authorization. We welcome reports of vulnerabilities discovered in good faith, including those encountered during normal use of University services.

Limit authorized testing to what is necessary to confirm a vulnerability, avoid disrupting services or affecting other users, and stop testing and promptly notify Information Security once the vulnerability is confirmed or sensitive data is encountered. Do not modify or delete data, copy or download sensitive data, establish persistent access, access other systems through the vulnerability, or conduct denial-of-service, social engineering, or physical security testing. Coordinate public disclosure with Information Security, allow reasonable time for assessment and remediation, never publicly disclose sensitive data, and seek guidance before proceeding if you are unsure whether an activity is permitted.

Frequently Asked Questions

What is a security vulnerability?

A security vulnerability is a weakness in a system, application, or configuration that could compromise the confidentiality, integrity, or availability of University information or services. Examples include unauthorized access to information, unauthorized changes to data, or weaknesses that could disrupt services. You do not need to access sensitive data or fully exploit a suspected vulnerability before reporting it.

Where do I report security vulnerabilities?

The preferred method is to submit vulnerability reports through the Report a Security Vulnerability form or by sending an email to informationsecurity@villanova.edu with details of the security issue. You can also contact the Technology Support Services at 610-519-7777, or for individuals with a Villanova Account, log in to support.villanova.edu and click Get Started. Regardless of the method of reporting a vulnerability, Information Security will review the security issue reported and follow up accordingly. 

What information should I include in my vulnerability report?

When reporting, please try to include the following:

  • A detailed description of the issue, including steps to reproduce it safely
  • A contact email address for follow-up questions
  • The affected system, application, URL, or IP address, if known
  • The potential security impact and when the issue was observed
  • Relevant screenshots, logs, or other supporting information, with sensitive information removed

Do not include passwords, access tokens, or sensitive personal information in your report. If sensitive information is necessary to explain the issue, contact Information Security to arrange an appropriate method for sharing it. Submit what you know even if some details are unavailable.

What happens after I submit a report?

Information Security will acknowledge receipt when contact information is provided, evaluate the report, and contact you if additional information is needed. Validated vulnerabilities will be prioritized based on their risk and potential impact. Remediation timelines may vary depending on the issue’s complexity and any dependencies on vendors or other parties. We will provide updates as appropriate, although some investigation or remediation details may remain confidential.

Where is your security.txt file?

Villanova University publishes a security.txt file to provide security researchers and others with information about how to report potential security vulnerabilities.

The file is available at: https://www.villanova.edu/.well-known/security.txt 

Do you provide a bug bounty?

Villanova University presently does not offer a financial bug bounty. If a vulnerability you report is considered new in our vulnerability tracking system, and can be reproduced and is rated as critical, upon remediation of the vulnerability by Villanova University and/or the vendor, the participant will receive a letter of recognition from Information Security and their name will be added to the list of successful bug bounty hunters. 


Visit the Vulnerability Management: Getting Started article to learn more about Vulnerability Management.