Third Party Index

Snapshot 22027

Document
Security advisories
URL
https://docs.elmah.io/vulnerability-disclosure-program/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
48647 bytes
SHA-256 (raw)
c8d8fac628543d1d46306e370e00bf083949138d62eebd27f0c624bcb89e47c9
SHA-256 (normalized text)
2f66e3c88bd3d2848507bd41b6b3fcc4789cc2bc1eb9fb7fc30753abf61761db

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Have a question ?
Ask anything and Bugster will be ready to answer and help you.
Getting Started
Quick start
Authentication
Integrations high level overview
ASP.NET
Logging from WebForms
Logging from ASP.NET MVC
Logging from Web API
Logging from Web Pages
Logging from a running website on IIS
Logging from a running website on Azure
Logging custom data
Logging errors programmatically
Logging to multiple logs
Remove sensitive form data
Setting application name
Configure elmah.io manually
Configure elmah.io from code
Logging through a HTTP proxy
Use multiple logs for different environments
Specify API key and log ID through appSettings
ELMAH and custom errors
Logging from a custom HTTP module
ASP.NET troubleshooting
ASP.NET Core
Logging from ASP.NET Core
Logging from Microsoft.Extensions.Logging
Logging from Blazor
Logging from SignalR
Using different logs per environment in ASP.NET Core
Logging breadcrumbs from ASP.NET Core
Roslyn analyzers for elmah.io and ASP.NET Core
ASP.NET Core troubleshooting
Logging Frameworks
Logging from Serilog
Logging from log4net
Logging from NLog
Logging from Microsoft.Extensions.Logging
Logging from Logary
Logging from JSNLog
JavaScript
Logging from JavaScript
Logging from Angular
Logging from React
Logging from Vue
Logging from SvelteKit
Source maps
JavaScript troubleshooting
CMS/Blogs
Logging from Umbraco
Logging from Sitefinity
Logging from BlogEngine.NET
Logging from Orchard
Logging from Piranha CMS
Mobile
Logging from Xamarin
Logging from Uno
Logging from MAUI
Logging from something else
Logging from WCF
Logging from CoreWCF
Logging from Azure Functions
Logging from Isolated Azure Functions
Logging from PowerShell
Logging from WPF
Logging from WinUI
Logging from Windows Forms
Logging from Entity Framework Core
Logging from C# and console applications
Logging from OpenTelemetry
Logging from HttpClient
Logging from AWS Beanstalk
Logging from AWS Lambdas
Logging from ServiceStack
Logging from DevExpress (eXpressApp Framework)
Logging from Google Cloud Functions
Logging from System.Diagnostics
Logging from Azure WebJobs
Logging from Nancy
Apps and Integrations
Slack
Microsoft Teams
Twilio
Jira
Azure Boards
GitHub
GitLab
Pipedream
Trello
YouTrack
Zapier
PagerDuty
ClickUp
ChatGPT
Fixes
BotBuster (deprecated)
IP Filter (deprecated)
Mailman (deprecated)
Request a new integration
Uptime Monitoring
Set up Uptime Monitoring
Missing server-side information on uptime errors
Allowing elmah.io uptime agents
Uptime Monitoring Troubleshooting
Heartbeats
Set up Heartbeats
Logging heartbeats from ASP.NET Core
Logging heartbeats from Azure Functions
Logging heartbeats from Isolated Azure Functions
Logging heartbeats from PowerShell
Logging heartbeats from cURL
Logging heartbeats from Umbraco
Logging heartbeats from Hangfire
Logging heartbeats from Coravel
Logging heartbeats from .NET Core Worker Services
Logging heartbeats from AWS Lambdas
Logging heartbeats from Windows Scheduled Tasks
Heartbeats Troubleshooting
Deployment Tracking
Set up Deployment Tracking
Create deployments from PowerShell
Create deployments from CLI
Create deployments from Octopus Deploy
Create deployments from Kudu
Create deployments from Azure DevOps Pipelines
Create deployments from Azure DevOps Releases
Create deployments from GitHub Actions
Create deployments from GitLab Pipelines
Create deployments from Umbraco Cloud
Create deployments from Bitbucket Pipelines
Create deployments from Atlassian Bamboo
MCP Server
Set Up MCP Server
elmah.io AI Plugin
Add MCP Server to Antigravity
Add MCP Server to Claude Code
Add MCP Server to Claude Desktop
Add MCP Server to ChatGPT
Add MCP Server to Codex
Add MCP Server to Cursor AI
Add MCP Server to Perplexity AI
Add MCP Server to Visual Studio
Add MCP Server to VS Code
Call MCP Server Using an API Key
CLI
CLI overview
Login
Logout
Deployments
Diagnose
Logs
Messages
Everything Else
Managing Organisations and Users
Where is my log ID
Where is my API key
Where is the permalink button
Where is my invoice / receipt
How to manage subscriptions, update credit cards, etc.
Managing Environments
Recommendations
How to delete my account
How to configure API key permissions
How to enable two-factor login
How to rename a log
How to include source code in log messages
How to search custom data
How to get the SQL tab to show up
How to configure and use Bugster
Creating Rules to Perform Actions on Messages
Query messages using full-text search
Tips and tricks to stay below your message limit
Use extended user details without email as ID
Adding version information
Bot detection
Include filename and line number in stack traces
How does the new detection work
How to correlate messages across services
How to get elmah.io to resolve the correct client IP
How to avoid emails getting classified as spam
How prices are calculated
How to run elmah.io in dark mode
How to show elmah.io dashboards on a big screen
Handle elmah.io downtime
Using the elmah.io extension for Visual Studio
Using the REST API
TLS 1.2 Requirement for api.elmah.io
Upgrade elmah.io from v4 to v5
Upgrade elmah.io from v3 to v4
Upgrade elmah.io from v2 to v3
Email troubleshooting
ELMAH and elmah.io differences
Vulnerability Disclosure Program (VDP)
Documentation menu
Vulnerability Disclosure Program (VDP)
Vulnerability Disclosure Program (VDP)
Scope
Rules of Engagement
What We're Looking For
Recognition
Communication & Conduct
How to Report
We take security seriously at elmah.io. To keep our platform and our customers safe, we invite security researchers and ethical hackers to report vulnerabilities responsibly.
This page outlines our Vulnerability Disclosure Program, what we are interested in, and how to report issues.
Scope
The following domains are in scope:
elmah.io
app.elmah.io
api.elmah.io
docs.elmah.io
blog.elmah.io
Any other subdomain owned by elmah.io.
Only vulnerabilities in production environments are eligible. Testing on demo environments or staging systems is not supported.
Rules of Engagement
Do no harm: Do not exploit vulnerabilities beyond what is necessary to demonstrate them.
Respect data: Never access, modify, or delete customer data. Use your own account where possible.
Responsible disclosure: Give us a reasonable time to investigate and fix issues before making anything public.
No disruption: Do not perform attacks that degrade our service (e.g., DDoS, spam, brute force).
What We're Looking For
We are particularly interested in:
Authentication or authorization bypasses
Cross-Site Scripting (XSS)
Cross-Site Request Forgery (CSRF)
NoSQL injection
Server-Side Request Forgery (SSRF)
Sensitive data exposure
Misconfigurations that could lead to compromise
Reports that are not eligible include:
Denial of Service (DoS / DDoS)
Public API keys used for JavaScript logging
Missing CAA DNS configuration
Session expiration and invalidation
Vulnerabilities in 3rd party services we use
Best-practice suggestions without a clear security impact
Missing security headers without an exploit scenario
Social engineering, phishing, or physical security attacks
Generally, issues produced by automated tools like security headers, etc.
Recognition
We appreciate contributions from the security community. Accepted reports may be rewarded with money or swag, depending on severity, novelty, and impact. Please note that reports of issues that are already known to us, are duplicates of previously submitted reports, or are otherwise not accepted, will not be eligible for a reward.
elmah.io assigns a severity level to all accepted issues. Each severity has a fixed reward range that determines whether the reporter receives money or swag and the size of the reward. These ranges are applied consistently across all submissions. We do not negotiate rewards outside the defined ranges. If a reporter believes that their finding deserves more than the assigned reward, we still adhere to the published ranges to ensure fairness and consistency.
Recognitions that are paid out in cash require the reporter to provide a valid invoice before the payment can be processed. The invoice must include the reporter's name or company details, address, and any other information needed for elmah.io to legally process the payment. Without a valid invoice, we are unable to issue cash rewards.
Communication & Conduct
We value respectful and professional communication. Most security researchers we work with follow responsible disclosure practices, but unfortunately, we have also experienced cases of hostile or threatening behavior.
To be clear:
Threats are not tolerated, including threats of disclosing vulnerabilities on the dark web, public forums, or elsewhere if certain demands are not met.
Respectful communication is required. We are here to collaborate, not to negotiate under pressure.
Immediate blocking if an email contains threats, aggressive language, or blackmail, the sender will be instantly blocked, and no further reports from that individual will be considered.
We are committed to working with researchers in good faith and expect the same in return.
How to Report
Please send reports to [email protected] with the following details:
A clear description of the vulnerability.
Steps to reproduce, including code snippets or screenshots.
The potential impact if exploited.
Your contact information.
We aim to respond to initial reports within 72 hours.
This article was brought to you by the elmah.io team. elmah.io is the best error management system for .NET web applications. We monitor your website, alert you when errors start happening, and help you fix errors fast.
See how we can help you monitor your website for crashes Monitor your website
Have a question ?
Ask anything and Bugster will be ready to answer and help you.