A researcher emails the city's responsible-disclosure inbox with a clear XSS proof against the citizen portal instead of posting the bug publicly. How should the municipality treat this channel within vulnerability management?
Select an answer to reveal the explanation.
Short Explanation
A good disclosure program is like a tip line for city hall—researchers who play by the rules hand you XSS details so you can fix them before the evening news. Treat that inbox as a real vuln-identification path, not spam to ignore or a reason to go nuclear.
Full Explanation
Responsible disclosure and bug-bounty programs invite ethical reporting of vulnerabilities so organizations learn about issues that scanners may miss. Triaging portal XSS reports through those channels is a recognized identification activity in vulnerability management. Rejecting valid reports, publicizing exploit details prematurely, or punishing compliant researchers undermines the program and delays remediation.