Vulnerability Details CVE-2020-24900
The default installation of Krpano Panorama Viewer version <=1.20.8 is prone to Reflected XSS due to insecure XML load in file /viewer/krpano.html, parameter xml.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.9%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2020-24900
-
cpe:2.3:a:krpano:krpano:1.20
-
cpe:2.3:a:krpano:krpano:1.20.1
-
cpe:2.3:a:krpano:krpano:1.20.2
-
cpe:2.3:a:krpano:krpano:1.20.3
-
cpe:2.3:a:krpano:krpano:1.20.4
-
cpe:2.3:a:krpano:krpano:1.20.5
-
cpe:2.3:a:krpano:krpano:1.20.6
-
cpe:2.3:a:krpano:krpano:1.20.7
-
cpe:2.3:a:krpano:krpano:1.20.8