Pannellum Cross-Site Scripting due to data not being sanitized for URIs or vbscript
Moderate severity
GitHub Reviewed
Published
Nov 22, 2019
in
mpetroff/pannellum
•
Updated Jan 11, 2023
Description
Published to the GitHub Advisory Database
Nov 22, 2019
Reviewed
Jun 16, 2020
Last updated
Jan 11, 2023
Versions of
pannellum
prior to 2.5.6 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize URLs for data URIs, which may allow attackers to execute arbitrary code in a victim's browser.Recommendation
Upgrade to version 2.5.6 or later.
References