CVE-2020-24901 describes a Reflected Cross-Site Scripting (XSS) vulnerability in the default installation of Krpano Panorama Viewer versions up to and including 1.20.8. This flaw, rated Medium severity (CVSS 6.1), allows an attacker to inject malicious scripts via the "plugin[test].url" parameter in the "viewer/krpano.html" file, requiring user interaction to trigger. While there is no public exploit code or Metasploit/Nuclei modules, the vulnerability has been observed in a spam campaign abusing major organizations' sites, indicating some level of real-world exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.20.8CPE matchmatch criteria | cpe:2.3:a:krpano:krpano:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.