BugCrowd Bug Bounty Disclosure: P5 – Cross site scripting – XSS – maxmuxammil
Cross site scripting - XSS Cross site scripting - XSS Researcher: maxmuxammil Engagement: National Aeronautics and Space Administration (NASA) -...
Cross site scripting - XSS Cross site scripting - XSS Researcher: maxmuxammil Engagement: National Aeronautics and Space Administration (NASA) -...
Session ID Disclosure via Referer Header to Third-Party Domains (nspires.nasaprs.com) Session ID Disclosure via Referer Header to Third-Party Domains (nspires.nasaprs.com)...
Unauthorised Access to GoAccess Logs on https://mwsci.jpl.nasa.gov Unauthorised Access to GoAccess Logs on https://mwsci.jpl.nasa.gov Researcher: green_hats Engagement: National Aeronautics and...
Public Exposure of NASA FTP Credentials in CORAL Document (PDF Hosted on Google Docs) Public Exposure of NASA FTP Credentials...
Reflected XSS in Multiple Endpoints on GSFC Subdomain Reflected XSS in Multiple Endpoints on GSFC Subdomain Researcher: Rahul-Hoysala Engagement: National...
Exposed Emails and Names on https://mttc.jpl.nasa.gov/api/retrieve-certs.php Exposed Emails and Names on https://mttc.jpl.nasa.gov/api/retrieve-certs.php Researcher: green_hats Engagement: National Aeronautics and Space Administration...
Source Code Disclosure Source Code Disclosure Researcher: oversudo Engagement: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program Disclosed...
Reflected XSS in `type` parameter on nlsp.nasa.gov Reflected XSS in `type` parameter on nlsp.nasa.gov Researcher: Marcel_Malaeb Engagement: National Aeronautics and...
internal IP Disclosure via Public DNS Record (blue.guest.hq.nasa.gov) internal IP Disclosure via Public DNS Record (blue.guest.hq.nasa.gov) Researcher: Theekshana_kusal Engagement: National...
open redirect vulnerability occurring at https://keycloak.shared-services.staging.appdat.jsc.nasa.gov/ open redirect vulnerability occurring at https://keycloak.shared-services.staging.appdat.jsc.nasa.gov/ Researcher: uko3211 Engagement: National Aeronautics and Space Administration...
Publicly editable Google Slides linked from nasa.gov enables unauthorized content modification (content integrity & brand abuse risk Publicly editable Google...
Sensitive NASA Jira & Employee Data Exposure via Public JSFiddle Sensitive NASA Jira & Employee Data Exposure via Public JSFiddle...
Directory Listing Vulnerability Directory Listing Vulnerability Researcher: Vinit06 Engagement: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program Disclosed...
Public Exposure of PII of NASA Meeting Registrations Public Exposure of PII of NASA Meeting Registrations Researcher: chirag8023 Engagement: National...
Members can enumerate and delete organization invites Members can enumerate and delete organization invites Researcher: Engagement: PostHog Vulnerability Disclosure Engagement...
Details of the collaboration between NASA and Inmarsat Government and the type of contract Details of the collaboration between NASA...
Publicly Editable Google Docs Linked from NASA SnowEx PPT Publicly Editable Google Docs Linked from NASA SnowEx PPT Researcher: Engagement:...
Reflected Cross-Site Scripting (XSS) on www.nasa.gov/search/search.jsp Reflected Cross-Site Scripting (XSS) on www.nasa.gov/search/search.jsp Researcher: madhu873 Engagement: National Aeronautics and Space Administration...
NASA Terminal Facility Guidelines for Unauthorized Disclosure of Personal Information (PII) NASA Terminal Facility Guidelines for Unauthorized Disclosure of Personal...
Publicly Accessible .env File Exposing Hardcoded Credentials on NASA’s Git Repository Publicly Accessible .env File Exposing Hardcoded Credentials on NASA’s...
Leak of usernames from a private website Leak of usernames from a private website Researcher: Engagement: National Aeronautics and Space...
Unauthorized Disclosure of PII via Internal NASA Doc Vulnerability Unauthorized Disclosure of PII via Internal NASA Doc Vulnerability Researcher: Black_charon...
Unauthenticated metadata disclosure of protected NASA flight reports and mission schedules via /ajax/activity Unauthenticated metadata disclosure of protected NASA flight...
Critical Identity and Communication Data Exposed in Unprotected NASA Hangar Demolition Doc Vulnerability Critical Identity and Communication Data Exposed in...