Executive brief
Advanced Guestbook is an open-source script used to add visitor comment sections to websites. A security flaw in the administrative interface allows an attacker with basic login credentials to inject malicious scripts into the 'smilies' management page. If a site administrator views this page, the script could execute, potentially leading to unauthorized actions or the theft of administrative session information.
Technical details
A persistent cross-site scripting (XSS) vulnerability exists in Advanced Guestbook 2.4.4 due to improper neutralization of user-supplied input in the smilies administration interface. An authenticated attacker can submit a specially crafted POST request to admin.php, injecting JavaScript into the 's_emotion' parameter. This script is stored on the server and executes in the context of any administrator who subsequently visits the smilies management tab. This can be used to perform unauthorized administrative actions or hijack administrator sessions. While the vulnerability was disclosed in 2021, it was formally cataloged in 2026; no official patch is currently documented in the advisory.
Affected products
- Ampps Advanced Guestbook 2.4.4
Timeline
- 2021-05-17: disclosed: Original exploit published on Exploit-DB
- 2026-05-10: advisory: CVE published/updated by VulnCheck and NVD