CVE-2023-53920
MEDIUMPodcastGenerator 3.2.9 - Stored Cross-Site Scripting via Podcast Title Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-53920. PoCs published by Mirabbas Ağalarov.
AI-analyzed exploit summary This exploit demonstrates multiple stored XSS vulnerabilities in PodcastGenerator 3.2.9. It includes detailed steps and HTTP requests to trigger XSS payloads in different sections of the application, such as episode titles, freebox content, and podcast details.
Description
PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the podcast title field accessible through the podcast details interface (podcast_details.php). Malicious JavaScript payloads injected into the podcast title execute when users visit the application's home page.
Exploits (1)
This exploit demonstrates multiple stored XSS vulnerabilities in PodcastGenerator 3.2.9. It includes detailed steps and HTTP requests to trigger XSS payloads in different sections of the application, such as episode titles, freebox content, and podcast details.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N