PT-2021-19919 · Poddycast+1 · Poddycast+1

Jamie Slome

+1

·

Published

2021-08-03

·

Updated

2022-04-25

·

CVE-2021-32772

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Poddycast versions prior to 0.8.1
Description The application does not clean the HTML characters of the podcast information obtained from the Feed, which allows the injection of HTML and JS code, resulting in cross-site scripting. As Poddycast is made with Electron, this cross-site scripting can be scaled to remote code execution, making it possible to execute commands on the machine where the application is running.
Recommendations For versions prior to 0.8.1, update to version 0.8.1 to resolve the issue. As a temporary workaround, consider restricting the use of podcast information obtained from untrusted Feeds to minimize the risk of exploitation.

Fix

XSS

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-32772
GHSA-WJMH-9FJ2-RQH6

Affected Products

Electron
Poddycast