CVE-2019-13949: Syguestbook a5 Project Syguestbook a5

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

SyGuestBook A5 Version 1.2 has no CSRF protection mechanism, as demonstrated by CSRF for an index.php?c=Administrator&a=update admin password change.

Affected products

Published 2019-07-18. Last modified 2026-06-17.