PT-2025-51300 · Unknown · @Lex Guestbook

Cracker

·

Published

2025-12-15

·

Updated

2025-12-21

·

CVE-2023-53882

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions JLex GuestBook version 1.6.4
Description The software contains a reflected cross-site scripting issue in the q URL parameter. This allows attackers to inject malicious scripts. Attackers can create malicious links with XSS payloads to potentially steal session tokens or execute arbitrary JavaScript in a victim’s browser.
Recommendations Update JLex GuestBook to a newer version that addresses this issue. As a temporary workaround, sanitize the q URL parameter to prevent the injection of malicious scripts.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-53882

Affected Products

@Lex Guestbook