Known Vulnerabilities for Syguestbook A5 by Syguestbook A5 Project
Listed below are 3 of the newest known vulnerabilities associated with "Syguestbook A5" by "Syguestbook A5 Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-13950 json | index.php?c=admin&a=index in SyGuestBook A5 Version 1.2 has stored XSS via a reply to a comment. | 5.4 - MEDIUM | 2019-07-18 | 2019-07-19 |
| CVE-2019-13949 json | SyGuestBook A5 Version 1.2 has no CSRF protection mechanism, as demonstrated by CSRF for an index.php?c=Administrator&a=updat... | 8.8 - HIGH | 2019-07-18 | 2019-07-19 |
| CVE-2019-13948 json | SyGuestBook A5 Version 1.2 allows stored XSS because the isValidData function in include/functions.php does not properly bloc... | 5.4 - MEDIUM | 2019-07-18 | 2019-07-19 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Syguestbook A5 Project | Syguestbook A5 | 1.2 |