Report a vulnerability privately through this repository's GitHub "Report a vulnerability" form (Security tab → Advisories) — never as a public issue.
You should expect an acknowledgement within 7 days.
This policy covers this repository (opensoft/openDox-code) only. For the
openDox project overall, see the security policy in the assembly root,
opensoft/openDox.