Unauthenticated Error-Based SQL Injection in HEASARC W3Browse w3hdprods.pl

Disclosed by
Anon0x0
Summary by Anon0x0

Unauthenticated Error-Based SQL Injection

The vulnerability allowed an unauthenticated attacker to execute arbitrary SQL queries against the backend PostgreSQL database, potentially enabling the extraction of sensitive astronomical observation metadata from multiple major NASA space mission archives.

The report was triaged quickly and the vulnerability was fully resolved by the NASA team on July 9, 2026.

Special thanks to the NASA security team for their prompt handling of this report.

Activity