Description
Podcast Generator 3.1 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unfiltered JavaScript code in the long_description parameter. Attackers can inject script tags through episode creation or editing requests to execute arbitrary JavaScript when other users view the episode details.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
Ayşenur KARAASLAN
References
www.exploit-db.com/exploits/49866 (ExploitDB-49866)
podcastgenerator.net/demoV2/ (Official Product Homepage)
podcastgenerator.net/download (Product Reference)
www.vulncheck.com/...oss-site-scripting-via-long-description (VulnCheck Advisory: Podcast Generator 3.1 Persistent Cross-Site Scripting via long_description)