VYPR

Pannellum

by Pannellum

CVEs (1)

  • CVE-2019-16763MedNov 22, 2019
    risk 0.24cvss 4.8epss 0.01

    In Pannellum from 2.5.0 through 2.5.4 URLs were not sanitized for data URIs (or vbscript:), allowing for potential XSS attacks. Such an attack would require a user to click on a hot spot to execute and would require an attacker-provided configuration. The most plausible…