Junglewise Threat Intelligence

CVE-2019-16763: Pannellum cross-site scripting in URL sanitization

CVE-2019-16763 · Severity: low · CVSS 3.1 · Published 2019-11-22

Vendors: npm.

Executive brief

Pannellum is a popular open-source web-based panoramic image viewer. Versions prior to 2.5.5 fail to sanitize URLs for data URIs and vbscript protocols, allowing attackers to inject malicious scripts. An attacker could craft a malicious configuration that executes arbitrary JavaScript in a victim's browser when they interact with a hotspot, potentially stealing session cookies or performing unauthorized actions.

Technical details

The vulnerability is a Cross-Site Scripting (CWE-79) flaw in Pannellum's URL handling. Pannellum fails to properly sanitize URLs in hotspot configurations for data URIs and vbscript: protocol handlers. An attacker can craft a malicious configuration file or hotspot URL containing data:text/html or vbscript: URIs that execute arbitrary JavaScript when a user clicks the hotspot. Exploitation requires user interaction (clicking a hotspot) and typically requires an attacker-provided configuration, but can be weaponized if Pannellum is embedded on an attacker-controlled page. The vulnerability was patched in version 2.5.5 by properly sanitizing URL inputs.

Affected products

  • Pannellum Project Pannellum 2.5.0 through 2.5.4

Timeline

  • 2019-11-22: disclosed
  • 2019-11-22: patched: Fixed in version 2.5.5

References

Related threats