CVE-2023-53882

MEDIUM

JLex GuestBook 1.6.4 - XSS

Title source: llm

Description

JLex GuestBook 1.6.4 contains a reflected cross-site scripting vulnerability in the 'q' URL parameter that allows attackers to inject malicious scripts. Attackers can craft malicious links with XSS payloads to steal session tokens or execute arbitrary JavaScript in victims' browsers.

Exploits (1)

exploitdb WORKING POC
by CraCkEr · textwebappsphp
https://www.exploit-db.com/exploits/51647

Scores

CVSS v4 5.1
EPSS 0.0009
EPSS Percentile 24.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

Details

CWE
CWE-79
Status published
Products (1)
jlexart/JLex GuestBook 1.6.4
Published Dec 15, 2025
Tracked Since Feb 18, 2026