@MicroHellas
1. vB.org staff does not have control over the procedures used when a vulnerability is found in vBulletin itself. If you want to discuss the Jelsoft procedures, then please post it as a suggestion at vbulletin.com.
2. With our current procedures we will inform both the users that have installed a modification and the author at the same time if the vulnerability found is serious. The reason members are notified by email and the author by PM is merely using the tools we have available. The author is also informed on the details of the vulnerability found. We have no way of knowing if an author will read his email faster then a PM, and he/she could have email notifications of a PM. Also the author could have disabled Email as contact method, so the best way to contact them (that will always work) is by PM.
We are however at this time prepairing new procedures making it easier to communicate with the author when a vulnerability is found.
Also please note the even though we are a community that is build upon the input of many coders, if a vulnerability is found our primary goal is to protect the members.
|