Vulnerabilities
Vulnerable Software
Krpano:  >> Krpano  >> 1.20  Security Vulnerabilities
Reflected Cross-Site Scripting (rXSS) in krpano before version 1.23.2 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the victim's browser via a crafted URL to the passQueryParameters function with the xml parameter enabled.
CVSS Score
6.1
EPSS Score
0.0
Published
2025-11-29
The default installation of Krpano Panorama Viewer version <=1.20.8 is prone to Reflected XSS due to insecure XML load in file /viewer/krpano.html, parameter xml.
CVSS Score
6.1
EPSS Score
0.002
Published
2021-01-07
The default installation of Krpano Panorama Viewer version <=1.20.8 is vulnerable to Reflected XSS due to insecure remote js load in file viewer/krpano.html, parameter plugin[test].url.
CVSS Score
6.1
EPSS Score
0.001
Published
2021-01-07


Contact Us

Shodan ® - All rights reserved