TSguestbook 2.1 Message Field HTML Injection Vulnerability
|| CVE: N/A
||Vulnerable App: N/A
It has been reported that TSguestbook may be prone to HTML injection attacks. The problem is said to occur due to insufficient sanitization of user-supplied input within the 'message' field. As a result, an attacker may post a guestbook entry including malicious HTML or script code within the said field. This could result in the execution of arbitrary code within the browser of an unsuspecting guestbook user.
Name: Zone-h Security Team