CVE-2019-13949: Syguestbook a5 Project Syguestbook a5
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
SyGuestBook A5 Version 1.2 has no CSRF protection mechanism, as demonstrated by CSRF for an index.php?c=Administrator&a=update admin password change.
Affected products
- Syguestbook a5 Project Syguestbook a5: version 1.2 only
Published 2019-07-18. Last modified 2026-06-17.