Reporting a vulnerability
If you believe you have found a security vulnerability in ifm.lu, the portal or the platform behind it, please tell us. We appreciate every report made in good faith.
How to report
Send an e-mail to e-mail@cetl.lu with:
- a description of the vulnerability and where it occurs (URL, component);
- the steps to reproduce it;
- the impact you expect;
- how we can reach you for questions.
Please do not include personal data of others, and do not access, change or delete data that is not yours. Do not use the vulnerability beyond what is needed to show it, and give us reasonable time to fix it before you disclose it.
We confirm receipt, assess the report and keep you informed of the outcome.
Reporting through CIRCL
You can also report the vulnerability to CIRCL, the Computer Incident Response Center Luxembourg. Under the Law of 5 May 2026 on cybersecurity, CIRCL is the national coordinator for vulnerability disclosure. It passes the report on to us and, if you wish, keeps your identity anonymous.
The machine-readable contact details are published at /.well-known/security.txt.