Description

Multiple Cross-Site Scripting (XSS) vulnerabilities were discovered in a subdomain of NASA.gov web application. The vulnerability allowed injection of arbitrary JavaScript code through unsanitized input parameters.

Impact

XSS vulnerabilities could allow attackers to steal session cookies, redirect users to malicious sites, or deface NASA web pages.

Solution

NASA security team was notified and the vulnerabilities were patched.

References