CVE-2023-53918
MEDIUMPodcastGenerator 3.2.9 - Stored Cross-Site Scripting in Episode Title Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-53918. PoCs published by Mirabbas Ağalarov.
AI-analyzed exploit summary This exploit demonstrates multiple stored XSS vulnerabilities in PodcastGenerator 3.2.9. It includes detailed steps and HTTP requests to trigger XSS payloads in different sections of the application, such as episode titles, freebox content, and podcast details.
Description
PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the episode title field accessible through the episodes upload interface (episodes_upload.php). Malicious JavaScript payloads injected into episode titles execute when administrators view the episodes list page (episodes_list.php).
Exploits (1)
This exploit demonstrates multiple stored XSS vulnerabilities in PodcastGenerator 3.2.9. It includes detailed steps and HTTP requests to trigger XSS payloads in different sections of the application, such as episode titles, freebox content, and podcast details.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N