CVE-2023-53882

MEDIUM

JLex GuestBook 1.6.4 - Reflected Cross-Site Scripting via URL Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-53882. PoCs published by CraCkEr.

AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in JLex GuestBook 1.6.4 via the 'q' GET parameter. The provided payload triggers a JavaScript confirmation dialog when the malicious URL is accessed.

Description

JLex GuestBook 1.6.4 contains a reflected cross-site scripting vulnerability in the 'q' URL parameter that allows attackers to inject malicious scripts. Attackers can craft malicious links with XSS payloads to steal session tokens or execute arbitrary JavaScript in victims' browsers.

Exploits (1)

exploitdb WORKING POC
by CraCkEr · textwebappsphp
https://www.exploit-db.com/exploits/51647

This exploit demonstrates a reflected XSS vulnerability in JLex GuestBook 1.6.4 via the 'q' GET parameter. The provided payload triggers a JavaScript confirmation dialog when the malicious URL is accessed.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: JLex GuestBook 1.6.4
No auth needed
Prerequisites: victim must click on a crafted URL
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/51647
Various Sources product
https://jlexart.com/

Scores

CVSS v4 5.1
EPSS 0.0005
EPSS Percentile 16.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
jlexart/JLex GuestBook 1.6.4
Published Dec 15, 2025
Tracked Since Feb 18, 2026