Executive brief
Pannellum is a popular open-source web-based panoramic image viewer. Versions prior to 2.5.5 fail to sanitize URLs for data URIs and vbscript protocols, allowing attackers to inject malicious scripts. An attacker could craft a malicious configuration that executes arbitrary JavaScript in a victim's browser when they interact with a hotspot, potentially stealing session cookies or performing unauthorized actions.
Technical details
The vulnerability is a Cross-Site Scripting (CWE-79) flaw in Pannellum's URL handling. Pannellum fails to properly sanitize URLs in hotspot configurations for data URIs and vbscript: protocol handlers. An attacker can craft a malicious configuration file or hotspot URL containing data:text/html or vbscript: URIs that execute arbitrary JavaScript when a user clicks the hotspot. Exploitation requires user interaction (clicking a hotspot) and typically requires an attacker-provided configuration, but can be weaponized if Pannellum is embedded on an attacker-controlled page. The vulnerability was patched in version 2.5.5 by properly sanitizing URL inputs.
Affected products
- Pannellum Project Pannellum 2.5.0 through 2.5.4
Timeline
- 2019-11-22: disclosed
- 2019-11-22: patched: Fixed in version 2.5.5