PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Attackers can manipulate the 'shortdesc' parameter to trigger external HTTP requests to arbitrary endpoints during podcast episode creation.
Metrics
Affected Vendors & Products
References
History
Tue, 16 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 16 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Attackers can manipulate the 'shortdesc' parameter to trigger external HTTP requests to arbitrary endpoints during podcast episode creation. | |
| Title | PodcastGenerator 3.2.9 Blind Server-Side Request Forgery via XML Injection | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-16T17:03:47.087Z
Updated: 2025-12-16T17:15:45.855Z
Reserved: 2025-12-16T00:10:40.314Z
Link: CVE-2023-53899
No data.
Status : Received
Published: 2025-12-16T17:16:02.213
Modified: 2025-12-16T18:16:06.930
Link: CVE-2023-53899
No data.