PT-2025-51747 · Unknown · Podcast Generator
Mirabbas Ağalarov
·
Published
2025-12-16
·
Updated
2025-12-30
·
CVE-2023-53899
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PodcastGenerator version 3.2.9
Description
The software contains a blind server-side request forgery issue that allows attackers to inject XML. This can be triggered by manipulating the
shortdesc parameter in the episode upload form, enabling attackers to initiate HTTP requests to arbitrary endpoints during podcast episode creation.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, sanitize the
shortdesc parameter to prevent XML injection.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Podcast Generator