LiveActive security incident?Get immediate response
CVE Record

CVE-2019-13950: index.php?c=admin&a=index in SyGuestBook A5 Version 1.2 has stored XSS via a reply to a comment.

index.php?c=admin&a=index in SyGuestBook A5 Version 1.2 has stored XSS via a reply to a comment.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2019-13950 is a stored cross-site scripting issue in SyGuestBook A5 Version 1.2. A malicious reply to a comment can be saved and later run in a victim’s browser when viewed. Business impact depends on whether this legacy guestbook software is still deployed.

Executive priority

Treat this as a targeted legacy-web cleanup item, not an emergency unless the software is internet-facing or used by administrators. Prioritize inventory first because the official affected-product metadata is incomplete.

Technical view

The CVE describes stored XSS in index.php?c=admin&a=index through comment reply handling in SyGuestBook A5 Version 1.2. The provided records do not include CVSS, CWE, affected CPEs, active exploitation evidence, or an official vendor fix.

Likely exposure

Exposure is likely limited to organizations still running SyGuestBook A5 Version 1.2 or reused code from it. Public-facing guestbook or admin interfaces would increase relevance, but the source bundle provides no deployment prevalence data.

Exploitation context

The bundle does not show CISA KEV listing or active exploitation. Stored XSS typically requires attacker-controlled content to be saved and later viewed by an authenticated user or visitor, but this assessment should not be treated as confirmed exploitation.

Researcher notes

Evidence is sparse: CVE text and referenced research identify stored XSS, but no CVSS, CWE, CPE, patch, vendor advisory, or exploitation telemetry is included. Validate against the referenced SyGuestBook A5 code audit before assigning operational severity.

Mitigation direction

  • Inventory public sites for SyGuestBook A5 Version 1.2 or derived code.
  • Check vendor or project guidance for a fixed release or official workaround.
  • Restrict administrative reply access to trusted users and networks.
  • Apply contextual output encoding for stored comment replies if maintaining the code.
  • Review and remove suspicious stored guestbook replies.

Validation and detection

  • Confirm whether SyGuestBook A5 Version 1.2 exists in production or archives.
  • Review comment reply rendering for missing output encoding.
  • Check stored guestbook replies for unexpected HTML or script-like content.
  • Test in staging that saved replies render as inert text.
  • Document any compensating controls if no patch is available.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2019-13950 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.