BugCrowd Bug Bounty Disclosure: P3 – Reflected XSS in Multiple Endpoints on GSFC Subdomain – Rahul-Hoysala

Reflected XSS in Multiple Endpoints on GSFC Subdomain

Reflected XSS in Multiple Endpoints on GSFC Subdomain

Researcher: Rahul-Hoysala
Engagement: National Aeronautics and Space Administration (NASA) – Vulnerability Disclosure Program
Disclosed at: 2025-10-31T18:06:08Z
Priority: P3
Status: Resolved

Summary

Multiple endpoints were found on the GSFC subdomain that were vulnerable to non-self reflected cross-site scripting (XSS).

Activity Feed

Actor Details Timestamp (UTC)
Martin_NASA Martin_NASA published 2025-10-31T18:06:08Z
Rahul-Hoysala Rahul-Hoysala requested 2025-10-29T14:46:59Z
hexghost_bugcrowd hexghost_bugcrowd changed the state to to resolved 2025-10-15T06:53:31Z
Martin_NASA Martin_NASA changed the state to to unresolved 2025-10-08T19:44:28Z
hexghost_bugcrowd hexghost_bugcrowd sent a: message 2025-10-01T13:23:51Z
hexghost_bugcrowd hexghost_bugcrowd changed the state to to triaged 2025-10-01T13:23:40Z
Rahul-Hoysala Rahul-Hoysala created the submission 2025-10-01T11:45:51Z

Support Our Work

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

AI APIs OSINT driven New features