logo

Krpano XSS exploitation campaign (Campaign)

ID: 4dd95731-4edd-5689-8dae-3338faa2a2a4

STIX ID: report--4dd95731-4edd-5689-8dae-3338faa2a2a4

Feed Name: Wiz Cloud Threat Landscape

Threat Score
60/100

Date Published: 2025-02-26

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

The report describes the “360XSS” campaign exploiting Krpano’s CVE-2020-24901 reflected XSS (misuse of passQueryParameters) across over 350 high-traffic sites (including Yale and CNN). Adversaries injected Base64-encoded JavaScript via the xml parameter to redirect users to porn, casino, and spam pages or to embed fake content on legitimate domains, primarily to perform SEO poisoning and drive monetized traffic using hijacked subdomains and misconfigured cloud resources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.