CVE-2019-13948: Syguestbook a5 Project Syguestbook a5
Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.
SyGuestBook A5 Version 1.2 allows stored XSS because the isValidData function in include/functions.php does not properly block XSS payloads, as demonstrated by a crafted use of the onerror attribute of an IMG element.
Affected products
- Syguestbook a5 Project Syguestbook a5: version 1.2 only
Published 2019-07-18. Last modified 2026-06-17.