GHSA-7rjr-6xrm-45m8MediumCVSS 6.4

Podcast Generator 3.1 contains a persistent cross-site scripting vulnerability that allows...

Published
May 15, 2026
Last Modified
May 15, 2026

🔗 CVE IDs covered (1)

📋 Description

Podcast Generator 3.1 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unfiltered JavaScript code in the long_description parameter. Attackers can inject script tags through episode creation or editing requests to execute arbitrary JavaScript when other users view the episode details.

🔗 References (6)