GHSA-7rjr-6xrm-45m8MediumCVSS 6.4
Podcast Generator 3.1 contains a persistent cross-site scripting vulnerability that allows...
🔗 CVE IDs covered (1)
📋 Description
Podcast Generator 3.1 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unfiltered JavaScript code in the long_description parameter. Attackers can inject script tags through episode creation or editing requests to execute arbitrary JavaScript when other users view the episode details.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2021-47968
- https://podcastgenerator.net/demoV2
- https://podcastgenerator.net/download
- https://www.exploit-db.com/exploits/49866
- https://www.vulncheck.com/advisories/podcast-generator-persistent-cross-site-scripting-via-long-description
- https://github.com/advisories/GHSA-7rjr-6xrm-45m8