U.S. General Services Administration Program Statistics


View program

17 total issues disclosed

$0 total paid publicly

Most disclosed (3 disclosures) — Information Disclosure



Disclosed Reports


Report Title Vulnerability Type Disclosed By Severity Disclosed on
access nagios dashboard using default credentials in ** omon1.fpki.gov, 3.220.248.203** Improper Access Control - Generic ahmed0x0mahmoud Critical 2022-10-21
User information disclosed via API Information Disclosure toormund High 2022-10-19
Registered users contact information disclosure on salesforce lightning endpoint https://disposal.gsa.gov Information Disclosure rptl High 2022-06-06
Read Other Users Reports Through Cloning Insecure Direct Object Reference (IDOR) imthatt Medium 2022-05-26
Account takeover leading to PII chained with stored XSS Improper Authentication - Generic imthatt High 2022-04-16
IDOR at https://demo.sftool.gov/TwsHome/ScorecardManage/ via scorecard name Improper Access Control - Generic imthatt High 2022-03-17
[Transportation Management Services Solution 2.0] Improper authorization at tmss.gsa.gov leads to data exposure of all registered users Improper Authorization alexandrio Critical 2021-12-08
Unauthorized access to employee panel with default credentials. Authentication Bypass Using an Alternate Path or Channel 7azimo High 2021-11-13
Web Cache Poisoning leading to DoS Denial of Service letm3through Medium 2021-11-08
Path Traversal on meetcqpub1.gsa.gov allows attackers to see arbitrary file listings. Path Traversal 0x0luke Low 2021-10-02
e-mail verification bypass through interception & modification of response status Violation of Secure Design Principles rajeshpatil No rating 2021-09-02
Account takeover through multistage CSRF at https://autochoice.fas.gsa.gov/AutoChoice/changeQAOktaAnswer and ../AutoChoice/changePwOktaAnswer Cross-Site Request Forgery (CSRF) rajeshpatil Medium 2021-07-23
Weak password policy leading to exposure of administrator account access Misconfiguration rajeshpatil Critical 2021-05-20
TAMS registration details API for admins open at https://tamsapi.gsa.gov/user/tams/api/usermgmnt/pendingUserDetails/ Insecure Direct Object Reference (IDOR) skarsom High 2021-05-07
IDOR at training.smartpay.gsa.gov/reports/quizzes-taken-by-user Insecure Direct Object Reference (IDOR) alihassam95 Medium 2021-04-24
PHP info page disclosure Information Disclosure valluvarsploit_h1 Low 2021-04-14
CRLF INJECTION None supplied amannnnnnnnnnnnnnn Low 2021-04-10