My employer has blocked Scouting America website indicating it has a critical security vulnerability. They have details to share, but only want to share with a specific contact (not an open web forum) due to the nature of the security vulnerability.
I wasn’t sure where to post and ask, but figured this technology group might know?
Thanks,
Richard Cantzler, ASM T1855 Folsom, CA
@RichardCantzler
Typically all support requests must go through your local council to open a ticket with Scouting America Member Care.
1 Like
This sounds like an active vulnerability that could compromise the entire website. Is there a more urgent escalation path for those types of things?
Unfortunately it’s extremely easy and common to find security holes in websites these days using AI agents, so it would be beneficial for whomever is managing the engineering effort to allow for more rapid bug reporting than working through local councils if possible.
Unfortunately, no. Your best bet to potentially move the ball on that is to coordinate with your council to also note that issue when they raise it with national. Offer to be a point of contact if national needs more information on your issue. It may or may not work, but it might reduce the amount of “telephone” the broader issue of vulnerability reporting experiences.
1 Like