Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-53899

Опубликовано: 16 дек. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Attackers can manipulate the 'shortdesc' parameter to trigger external HTTP requests to arbitrary endpoints during podcast episode creation.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:podcastgenerator:podcast_generator:3.2.9:*:*:*:*:*:*:*

EPSS

Процентиль: 38%
0.00169
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 9.8
github
около 2 месяцев назад

PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Attackers can manipulate the 'shortdesc' parameter to trigger external HTTP requests to arbitrary endpoints during podcast episode creation.

EPSS

Процентиль: 38%
0.00169
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-918