BugCrowd Bug Bounty Disclosure: P5 – Reflected XSS on esto.nasa.gov allows arbitrary JavaScript execution and redirection – Faxcel

Reflected XSS on esto.nasa.gov allows arbitrary JavaScript execution and redirection

Reflected XSS on esto.nasa.gov allows arbitrary JavaScript execution and redirection

Researcher: Faxcel
Engagement: National Aeronautics and Space Administration (NASA) – Vulnerability Disclosure Program
Disclosed at: 2025-05-12T14:52:35Z
Priority: P5
Status: Informational

Summary

Self Reflected XSS

Activity Feed

Actor Details Timestamp (UTC)
Martin Martin published 2025-05-12T14:52:35Z
Faxcel Faxcel requested 2025-05-12T10:00:18Z
viper-bugcrowd viper-bugcrowd updated 2025-05-12T08:39:35Z
viper-bugcrowd viper-bugcrowd changed the state to to informational 2025-05-12T08:39:32Z
viper-bugcrowd viper-bugcrowd sent a: message 2025-05-12T08:39:29Z
Faxcel Faxcel created the submission 2025-05-11T04:51:11Z

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below

To keep up to date follow us on the below channels.