PT-2025-51747 · Unknown · Podcast Generator

Mirabbas Ağalarov

·

Published

2025-12-16

·

Updated

2025-12-30

·

CVE-2023-53899

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PodcastGenerator version 3.2.9
Description The software contains a blind server-side request forgery issue that allows attackers to inject XML. This can be triggered by manipulating the shortdesc parameter in the episode upload form, enabling attackers to initiate HTTP requests to arbitrary endpoints during podcast episode creation.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, sanitize the shortdesc parameter to prevent XML injection.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2023-53899

Affected Products

Podcast Generator