Vulnerability Description
index.php?c=admin&a=index in SyGuestBook A5 Version 1.2 has stored XSS via a reply to a comment.
CVSS Score
5.4
MEDIUM
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Syguestbook A5 Project | Syguestbook A5 | 1.2 |
Related Weaknesses (CWE)
References
- https://fragrant10.github.io/2019/02/22/SyGuestBookA5%E4%BB%A3%E7%A0%81%E5%AE%A1ExploitThird Party Advisory
- https://github.com/fragrant10/fragrant10.github.io/blob/master/_posts/2019-02-22ExploitThird Party Advisory
- https://fragrant10.github.io/2019/02/22/SyGuestBookA5%E4%BB%A3%E7%A0%81%E5%AE%A1ExploitThird Party Advisory
- https://github.com/fragrant10/fragrant10.github.io/blob/master/_posts/2019-02-22ExploitThird Party Advisory
FAQ
What is CVE-2019-13950?
CVE-2019-13950 is a vulnerability with a CVSS score of 5.4 (MEDIUM). index.php?c=admin&a=index in SyGuestBook A5 Version 1.2 has stored XSS via a reply to a comment.
How severe is CVE-2019-13950?
CVE-2019-13950 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-13950?
Check the references section above for vendor advisories and patch information. Affected products include: Syguestbook A5 Project Syguestbook A5.