Pannellum Cross-Site Scripting due to data not being sanitized for URIs or vbscript
- Severity:
- Medium
Description
Versions of pannellum prior to 2.5.6 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize URLs for data URIs, which may allow attackers to execute arbitrary code in a victim’s browser.
Recommendation
Update the pannellum package to the latest compatible version. Followings are version details:
- Affected version(s): >= 2.5.0, < 2.5.5
- Patched version(s): 2.5.5
References
Related Issues
- markdown-it-toc Cross-site Scripting due to title of generated toc and contents of header not being escaped - CVE-2020-28455
- AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes - CVE-2019-14863
- Cross-Site Scripting in fileview - CVE-2019-15602
- Cross-Site Scripting in seeftl - CVE-2019-15603
You might also like:
- Tags:
- npm
- pannellum
Anything's wrong? Let us know Last updated on January 11, 2023


