PT-2025-48752 · Lookyloo · Lookyloo
Published
2025-12-02
·
Updated
2025-12-05
·
CVE-2025-66459
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Lookyloo versions prior to 1.35.3
Description
Lookyloo is a web interface used to capture website pages and display a tree of domains that interact with each other. A cross-site scripting (XSS) issue can occur when a user submits URLs for capture, including one containing a HTML element that causes the capture to fail. The resulting error message, which includes the problematic URL, is then displayed without proper sanitization, leading to XSS. The issue is triggered when the error field is populated with the bad URL.
Recommendations
Update Lookyloo to version 1.35.3 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lookyloo