Podcast Generator 3.1 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unfiltered JavaScript code in the long_description parameter. Attackers can inject script tags through episode creation or editing requests to execute arbitrary JavaScript when other users view the episode details.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 15 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Podcast Generator 3.1 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unfiltered JavaScript code in the long_description parameter. Attackers can inject script tags through episode creation or editing requests to execute arbitrary JavaScript when other users view the episode details. | |
| Title | Podcast Generator 3.1 Persistent Cross-Site Scripting via long_description | |
| First Time appeared |
Podcastgenerator
Podcastgenerator podcast Generator |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:podcastgenerator:podcast_generator:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Podcastgenerator
Podcastgenerator podcast Generator |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-15T18:36:34.085Z
Reserved: 2026-05-15T16:39:50.787Z
Link: CVE-2021-47968
No data.
Status : Received
Published: 2026-05-15T19:16:56.560
Modified: 2026-05-15T19:16:56.560
Link: CVE-2021-47968
No data.
OpenCVE Enrichment
No data.
Weaknesses