A cross-site scripting (XSS) vulnerability in the Krpano virtual browser system is being used by hackers to inject malicious scripts into hundreds of websites, aiming to corrupt search results and support a spam ads campaign.
See also: iMessage: Hackers trick you into disabling phishing protection

Security researcher Oleg Zaytsev, in a report published on The Hacker News, revealed that the campaign, dubbed 360XSS, affected over 350 websites. These include government portals, US state government websites, American universities, major hotel chains, news agencies, car dealerships, and several Fortune 500 companies.
All of these sites have one thing in common: They use Krpano, a popular integration framework, to create interactive virtual tours and VR experiences with 360° images and videos.
Zaytsev discovered Krpano's spam ads campaign when he came across an ad related to pornographic content appearing on Google Search, but accompanied by a domain that appeared to be associated with Yale University (“virtualtour.quantuminstitute.yale[.]edu”).
An important element of these URLs is an XML parameter that is intended to direct the website visitor to another URL, which belongs to another trusted website. This process is used to execute a Base64 through an XML document. Once decoded, the payload retrieves the pre-defined URL (such as an advertisement) from another equally legitimate website.
See also: WordPress: Critical vulnerabilities in Spam protection, Anti-Spam, FireWall plugin
The XML parameter included in the original URL, as displayed in search results, is part of a larger setting known as “passQueryParameters“. This is used when embedding a Krpano viewer in an HTML page. Its purpose is to pass HTTP parameters from the URL directly to the viewer.

When this option is enabled, there is a risk that a malicious user could run a malicious script in your browser using a specially crafted URL when you visit a vulnerable website.
The campaign exploits the Krpano framework, and has exploited this vulnerability to infiltrate over 350 websites, serving spam ads related to pornography, dietary supplements, online casinos, and disinformation sites. Some of these pages were also used to boost views on YouTube videos.
See also: Black Friday 2024: 77% of spam emails are scams
Cross-site scripting (XSS) is one of the most common vulnerabilities on the web. It occurs when an attacker exploits a system weakness to inject malicious code into a website, and that code is executed by the visitor's browser.
How can you protect yourself? To protect yourself from such attacks, it is important to be careful about the links you follow online. Keep your software up to date and use anti-malware tools. In addition, website developers must ensure that user data is not processed without proper sterilization and verification. It is important to keep your browser up to date and use add-ons that offer additional layers of security, such as uBlock Origin to block suspicious scripts.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
