BugCrowd Bug Bounty Disclosure: P1 – Authentication Bypass + exposure of PII + reflected XSS – snillx

Authentication Bypass + exposure of PII + reflected XSS

Authentication Bypass + exposure of PII + reflected XSS

Researcher: snillx
Engagement: National Aeronautics and Space Administration (NASA) – Vulnerability Disclosure Program
Disclosed at: 2025-08-07T15:49:38Z
Priority: P1
Status: Resolved

Summary

During a review of a subdomain in appdat.jsc.nasa.gov, three critical vulnerabilities were identified:

Authentication Bypass: **The Keycloak “ordem-production” realm accepts **default credentials, granting full access without authorization.

Sensitive Information Exposure: Authenticated users can view internal staff PII, full names, mail codes, phone numbers and email addresses on the About page, enabling spear-phishing and privacy violations.

Reflected XSS: The jobno parameter is not sanitized, allowing arbitrary JavaScript execution (e.g. cookie theft) after login.

Collectively, these issues enable unauthorized access, PII disclousure **and **session hijacking.

Activity Feed

Actor Details Timestamp (UTC)
Martin_NASA Martin_NASA published 2025-08-07T15:49:38Z
snillx snillx requested 2025-08-05T12:44:23Z
viper-bugcrowd viper-bugcrowd changed the state to to resolved 2025-08-05T12:29:51Z
snillx snillx sent a: message 2025-07-30T02:20:48Z
Medx Medx sent a: message 2025-07-29T15:07:43Z
Martin_NASA Martin_NASA changed the state to to unresolved 2025-07-25T14:08:57Z
brunoc_bugcrowd brunoc_bugcrowd sent a: message 2025-07-21T13:20:29Z
brunoc_bugcrowd brunoc_bugcrowd changed the state to to triaged 2025-07-21T13:20:21Z
brunoc_bugcrowd brunoc_bugcrowd updated 2025-07-21T13:17:25Z
snillx snillx created the submission 2025-07-20T19:22:36Z

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below

To keep up to date follow us on the below channels.