Description
Versions of pannellum prior to 2.5.6 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize URLs for data URIs, which may allow attackers to execute arbitrary code in a victim’s browser.
Recommendation
Update the pannellum package to the latest compatible version. Followings are version details:
- Affected version(s): >= 2.5.0, < 2.5.5
- Patched version(s): 2.5.5
References
Could your website be exposed too?
SmartScanner can check your website for Pannellum Cross-Site Scripting due to data not being sanitized for URIs or vbscript and gives you actionable findings to investigate.
Start a free scanRelated Issues
- markdown-it-toc Cross-site Scripting due to title of generated toc and contents of header not being escaped - CVE-2020-28455
- AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes - CVE-2019-14863
- Cross-Site Scripting in fileview - CVE-2019-15602
- Cross-Site Scripting in seeftl - CVE-2019-15603


