PT-2025-39430 · Unknown · Vulnerability-Lookup
Published
2025-09-25
·
Updated
2025-09-26
·
CVE-2025-60249
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
vulnerability-lookup version 2.16.0
Description
A cross-site scripting (XSS) issue exists in the handling of user-supplied input within the Bundles, Comments, and Sightings components of the software. Untrusted data was not properly sanitized before being rendered, potentially allowing attackers to inject arbitrary JavaScript into the application. The root cause was the unsafe use of
innerHTML and insufficient validation of dynamic URLs and model fields. The affected files include bundle.py, comment.py, and user.py. An attacker who can add bundles, comments, or sightings to a vulnerability-lookup instance can exploit this issue.Recommendations
Update to a newer version that contains a fix for this vulnerability.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vulnerability-Lookup