BugCrowd

BugCrowd Bug Bounty Disclosure: P5 – Unauthenticated metadata disclosure of protected NASA flight reports and mission schedules via /ajax/activity – madhu873

Unauthenticated metadata disclosure of protected NASA flight reports and mission schedules via /ajax/activity Unauthenticated metadata disclosure of protected NASA flight...

BugCrowd Bug Bounty Disclosure: P3 – Critical Identity and Communication Data Exposed in Unprotected NASA Hangar Demolition Doc Vulnerability – Black_charon

Critical Identity and Communication Data Exposed in Unprotected NASA Hangar Demolition Doc Vulnerability Critical Identity and Communication Data Exposed in...

BugCrowd Bug Bounty Disclosure: P3 – RXSS at `https://skyview.gsfc.nasa.gov/current/cgi/vo/sia.pl` – GxbNt

RXSS at `https://skyview.gsfc.nasa.gov/current/cgi/vo/sia.pl` RXSS at `https://skyview.gsfc.nasa.gov/current/cgi/vo/sia.pl` Researcher: GxbNt Engagement: National Aeronautics and Space Administration (NASA) - Vulnerability Disclosure Program Disclosed...

BugCrowd Bug Bounty Disclosure: P5 – Host Header Injection on Password-Reset Functionality Causes Unauthorized Redirect to Attacker-Controlled Domain Where a Users Could be Tricked into Entering Account Credentials for Account Takeover or PII Leak – Imshadab18