CVE-2023-53882
MEDIUMJLex GuestBook 1.6.4 - Reflected Cross-Site Scripting via URL Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-53882. PoCs published by CraCkEr.
AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in JLex GuestBook 1.6.4 via the 'q' GET parameter. The provided payload triggers a JavaScript confirmation dialog when the malicious URL is accessed.
Description
JLex GuestBook 1.6.4 contains a reflected cross-site scripting vulnerability in the 'q' URL parameter that allows attackers to inject malicious scripts. Attackers can craft malicious links with XSS payloads to steal session tokens or execute arbitrary JavaScript in victims' browsers.
Exploits (1)
This exploit demonstrates a reflected XSS vulnerability in JLex GuestBook 1.6.4 via the 'q' GET parameter. The provided payload triggers a JavaScript confirmation dialog when the malicious URL is accessed.
References (3)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N