PT-2025-39430 · Unknown · Vulnerability-Lookup

Published

2025-09-25

·

Updated

2025-09-26

·

CVE-2025-60249

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions vulnerability-lookup version 2.16.0
Description A cross-site scripting (XSS) issue exists in the handling of user-supplied input within the Bundles, Comments, and Sightings components of the software. Untrusted data was not properly sanitized before being rendered, potentially allowing attackers to inject arbitrary JavaScript into the application. The root cause was the unsafe use of innerHTML and insufficient validation of dynamic URLs and model fields. The affected files include bundle.py, comment.py, and user.py. An attacker who can add bundles, comments, or sightings to a vulnerability-lookup instance can exploit this issue.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-60249

Affected Products

Vulnerability-Lookup