NASA EOSDIS MODAPS SQL Injection Vulnerability
Vulnerability
A SQL injection vulnerability has been identified in NASA's Earth Observing System Data and Information System (EOSDIS) MODAPS version 8.1. The issue arises from improper input validation in the 'category' parameter, allowing attackers to manipulate HTTP GET requests, execute arbitrary SQL queries, and potentially access sensitive data. This vulnerability affects the MODAPS web application and its backend PostgreSQL database.
Impact
Exploitation of this vulnerability allows for SQL injection, where an attacker can execute arbitrary SQL queries. This could lead to unauthorized data access or manipulation within the application's database.
Remediation
NASA has confirmed this vulnerability and applied a fix.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
