It's possible to include malicious code into the "title"-field of the guestbook: "title": <script> some code</script>. If you want the script to work in the admin-account as well, you have to put a </td>-Tag in front of the <script>-Tag.
Log in to post a comment.