Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Abdulkadir Aydogan

#42198of 53,633
6.4Total CVSS
Vulnerabilities · 1
PT-2026-39524
6.4
2026-05-10
Unknown · Advanced Guestbook · CVE-2021-47950
**Name of the Vulnerable Software and Affected Versions** Advanced Guestbook version 2.4.4 **Description** A persistent cross-site scripting issue exists in the smilies administration interface. Authenticated attackers can inject malicious scripts by sending POST requests to the 'admin.php' endpoint using the `s emotion` parameter. These scripts execute when administrators access the smilies tab. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the `s emotion` parameter within the 'admin.php' endpoint.