By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Hackers Exploited Krpano Framework Flaw to Inject Spam Ads on 350+ Websites
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Hackers Exploited Krpano Framework Flaw to Inject Spam Ads on 350+ Websites
Tech News

Hackers Exploited Krpano Framework Flaw to Inject Spam Ads on 350+ Websites

By Viral Trending Content 6 Min Read
Share
SHARE

A cross-site scripting (XSS) vulnerability in a virtual tour framework has been weaponized by malicious actors to inject malicious scripts across hundreds of websites with the goal of manipulating search results and fueling a spam ads campaign at scale.

Security researcher Oleg Zaytsev, in a report shared with The Hacker News, said the campaign – dubbed 360XSS – affected over 350 websites, including government portals, U.S. state government sites, American universities, major hotel chains, news outlets, car dealerships, and several Fortune 500 companies.

“This wasn’t just a spam operation,” the researcher said. “It was an industrial-scale abuse of trusted domains.”

All these websites have one thing in common: A popular framework called Krpano that’s used to embed 360° images and videos to facilitate interactive virtual tours and VR experiences.

Zaytsev said he stumbled upon the campaign after coming across a pornography-related ad listed on Google Search but with a domain associated with Yale University (“virtualtour.quantuminstitute.yale[.]edu”).

Cybersecurity

A notable aspect of these URLs is an XML parameter that’s designed to redirect the site visitor to a second URL that belongs to another legitimate website, which is then used to execute a Base64-encoded payload via an XML document. The decoded payload, for its part, fetches the target URL (i.e., the ad) from yet another legitimate site.

The XML parameter passed in the original URL served in the search results is part of a broader configuration setting named “passQueryParameters” that’s used when embedding a Krpano panorama viewer into an HTML page. It’s specifically designed to pass HTTP parameters from the URL to the viewer.

The security issue here is that if the option is enabled, it opens the door to a scenario where an attacker could use a specially crafted URL to execute a malicious script in a victim’s web browser when the vulnerable site is visited.

Indeed, a reflected XSS flaw arising as a result of this behavior was disclosed in Krpano in late 2020 (CVE-2020-24901, CVSS score: 6.1), indicating that the potential for abuse has been publicly known for over four years.

While an update introduced in version 1.20.10 restricted “passQueryParameters” to an allowlist in an attempt to prevent such XSS attacks from taking place, Zaytsev found that explicitly adding the XML parameter to the allowlist reintroduced the XSS risk.

“Since version 1.20.10, Krpano’s default installation was not vulnerable,” the researcher told The Hacker News via email. “However, configuring passQueryParameter in combination with the XML parameter allowed external XML configuration via the URL, leading to an XSS risk.”

“The exploited versions I’ve come across were primarily older ones, predating version 1.20.10.”

The campaign, per Zaytsev, has leveraged this weakness to hijack over 350 sites to serve sketchy ads related to pornography, diet supplements, online casinos, and fake news sites. What’s more, some of these pages have been weaponized to boost YouTube video views.

The campaign is noteworthy, not least because it abuses the trust and credibility of legitimate domains to show up prominently in search results, a technique called search engine optimization (SEO) poisoning, which, in turn, is accomplished by abusing the XSS flaw.

“A reflected XSS is a fun vulnerability but on its own requires user interaction, and one of the biggest challenges is to make people click your reflected XSS link,” Zaytsev said. “So using search engines as a distribution platform for your XSS is a very creative and cool way to do it.”

Cybersecurity

Following responsible disclosure, the latest release of Krpano eliminates support for external configuration via the XML parameter, thereby mitigating the risk of XSS attacks even when the setting is used.

“Improved embedpano() passQueryParameters security: data-urls and external URLs are generally not allowed as parameter values anymore and URLs for the XML parameter are limited to be within the current folder structure,” according to the release notes for version 1.22.4 released this week.

It’s currently not known who is behind the massive operation, although the abuse of an XSS flaw to serve just redirects, as opposed to carrying out more nefarious attacks like credential or cookie theft, raises the possibility of an ad firm with questionable practices that’s serving these ads as a monetization strategy.

Users of Krpano are advised to update their installations to the latest version and set the “passQueryParameters” setting to false. Affected website owners are recommended to find and remove infected pages via Google Search Console.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Best Fitness Tracker 2026: Fitbits, Bands & Hybrids

Your Photos Are Probably Giving Away Your Location. Here’s How to Stop That

Critical Fortinet Forticlient EMS flaw now exploited in attacks

21 organisations currently adding to their engineering teams

M5 Ultra Mac Studio Leaks: 8K Video and GPU Benchmarks

TAGGED: Cyber Security, Cybersecurity, Digital Advertising, Incident response, Internet, SEO Manipulation, software security, Threat Intelligence, Vulnerability, web security, website security, XSS attack
Share This Article
Facebook Twitter Copy Link
Previous Article PlayStation Plus subscribers get Dragon Age: The Veilguard, 13 classic TMNT games in March
Next Article Samsung Galaxy Z Flip 7 Release Date, Price & Specs Rumours
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

As the Iran war drags on, ‘shell-shocked’ CEOs may soon break their silence on Trump
Business
XRP price outlook: relief bounce driven by Ripple CEO optimism
Crypto
Dimension 20 Is Finally Doing A Vampire: The Masquerade Campaign And I Am So Stoked
Gaming News
Brush up: How to plan a creative holiday in Europe
Travel
Best Fitness Tracker 2026: Fitbits, Bands & Hybrids
Tech News
Your Photos Are Probably Giving Away Your Location. Here’s How to Stop That
Tech News
Critical Fortinet Forticlient EMS flaw now exploited in attacks
Tech News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

As the Iran war drags on, ‘shell-shocked’ CEOs may soon break their silence on Trump

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
As the Iran war drags on, ‘shell-shocked’ CEOs may soon break their silence on Trump
March 30, 2026
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?