CVE-2023-53918

MEDIUM

PodcastGenerator 3.2.9 - Stored Cross-Site Scripting in Episode Title Field

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-53918. PoCs published by Mirabbas Ağalarov.

AI-analyzed exploit summary This exploit demonstrates multiple stored XSS vulnerabilities in PodcastGenerator 3.2.9. It includes detailed steps and HTTP requests to trigger XSS payloads in different sections of the application, such as episode titles, freebox content, and podcast details.

Description

PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the episode title field accessible through the episodes upload interface (episodes_upload.php). Malicious JavaScript payloads injected into episode titles execute when administrators view the episodes list page (episodes_list.php).

Exploits (1)

exploitdb WORKING POC
by Mirabbas Ağalarov · textwebappsphp
https://www.exploit-db.com/exploits/51454

This exploit demonstrates multiple stored XSS vulnerabilities in PodcastGenerator 3.2.9. It includes detailed steps and HTTP requests to trigger XSS payloads in different sections of the application, such as episode titles, freebox content, and podcast details.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: PodcastGenerator v3.2.9
Auth required
Prerequisites: Access to admin panel · Valid session cookie
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory, VDB Entry exploit
https://www.exploit-db.com/exploits/51454

Scores

CVSS v3 6.1
EPSS 0.0028
EPSS Percentile 19.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
podcastgenerator/podcast_generator 3.2.9
Podcastgenerator/PodcastGenerator 3.2.9
Published Dec 17, 2025
Tracked Since Feb 18, 2026