Critical information disclosure at https://www.doi.gov/

Disclosed by
tejaspawar172000's avatar
tejaspawar172000
Summary by tejaspawar172000

Can i disclose my?

Report details
  • Submitted

  • Target Location

    *.doi.gov
  • Target category

    Web App

  • VRT

    Sensitive Data Exposure > Disclosure of Known Public Information
  • Priority

    P5
  • Bug URL
    https://pdsimage2.wr.usgs.gov/data/
  • Description

    Summary :
    hello Team ,
    while Exploring Your Site https://www.doi.gov/ .I found that Search Parameter is vulnerable And it is diclosing the path that gives access to critical information.

    Vulnerable URL:-
    https://search.usa.gov/search?affiliate=doi.gov&query=%5c%22%3balert(%27XSS%27)%3b%2f%2f&commit=Search

    https://pdsimage2.wr.usgs.gov/data/

    image-2021-12-25T20:02:23.491Z.png

    Impact :-

    The impact here can be great because Attacker Is Able To Gain sensitive Information About target

    Step-by-step Reproduction Instructions :-
    1 . Go to https://www.doi.gov/
    2 . perform search operation using payload \";alert('XSS');//
    3 . It discloses the path
    https://pdsimage2.wr.usgs.gov/data/mgs-m-moc-na_wa-2-sdp-l0-v1.0/mgsc_1111/

    1. Go to below Path https://pdsimage2.wr.usgs.gov/data/mgs-m-moc-na_wa-2-sdp-l0-v1.0/mgsc_1111/ It is disclosing The Sensitive information.

    POC:

    20211226014134.mp4

    image-2021-12-25T20:17:48.698Z.png

    image-2021-12-25T20:26:14.511Z.png

Activity
  1. DOI_RPI’s avatar
    DOI_RPI Customer published the disclosure report

    ()

  2. tejaspawar172000’s avatar
    tejaspawar172000 requested disclosure

    ()

  3. chickenJoe’s avatarbugcrowd logo
    chickenJoe changed the state to Informational

    ()

  4. chickenJoe’s avatarbugcrowd logo
    chickenJoe updated VRT to Sensitive Data Exposure > Disclosure of Known Public Information

    ()

  5. chickenJoe’s avatarbugcrowd logo
    chickenJoe sent a message

    ()Edited

  6. tejaspawar172000’s avatar
    tejaspawar172000 created the submission

    ()