Description
PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the episode title field accessible through the episodes upload interface (episodes_upload.php). Malicious JavaScript payloads injected into episode titles execute when administrators view the episodes list page (episodes_list.php).
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
Mirabbas Ağalarov
References
www.exploit-db.com/exploits/51454
www.exploit-db.com/exploits/51454 (ExploitDB-51454)
podcastgenerator.net/ (Official Product Webpage)
www.vulncheck.com/...-site-scripting-via-episode-title-field (VulnCheck Advisory: PodcastGenerator Stored Cross-Site Scripting via Episode Title Field)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.