An issue was discovered in ViewerJS 0.5.8. A script from the component loads content via URL TAGs without properly sanitizing it. This leads to both open redirection and out-of-band resource loading.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.