Subject: [VDP] <Severity> — <Short Title>
1. Vulnerability Type: (e.g., IDOR, SQLi, Auth Bypass)
2. Affected Asset: (URL, endpoint, service)
3. Severity: Critical / High / Medium / Low
4. CVSS 3.1 Score: (with vector string)
5. Description: (what the vulnerability is)
6. Steps to Reproduce:
Step 1: ...
Step 2: ...
Step 3: ...
7. Proof of Concept: (curl commands, screenshots, video)
8. Impact: (what an attacker can achieve)
9. Suggested Fix: (optional but appreciated)
Response SLA. Acknowledge within 3 business days, triage + severity within 7 business days, fix or mitigation within 30 days for High / Critical. You will be kept informed at each stage.
Disclosure timeline. We coordinate publication with the reporter. Our target is public disclosure within 90 days of the initial report (sooner if a fix has shipped and the reporter agrees). We will request an extension, with reasoning, if a fix is in-flight at day-90.