Lookyloo Cross-Site Scripting Vulnerability
Vulnerability
A cross-site scripting (XSS) vulnerability has been identified in Lookyloo versions prior to 1.35.1. This issue arises from improper sanitization of user input, allowing HTML injection that could be exploited to execute scripts. On standard installations, the default Content Security Policy (CSP) mitigates the risk by preventing direct script execution, but the underlying vulnerability remains.
Impact
Exploitation of this vulnerability could lead to cross-site scripting, allowing for the injection and execution of malicious scripts in the user's browser.
Remediation
Users can upgrade to Lookyloo version 1.35.1 or later to address this vulnerability. If the default CSP configuration has been modified, it is recommended to revert to the original settings, as the default CSP effectively mitigates this issue.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
