Логотип exploitDog
bind:CVE-2023-53899
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-53899

Количество 2

Количество 2

nvd логотип

CVE-2023-53899

около 2 месяцев назад

PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Attackers can manipulate the 'shortdesc' parameter to trigger external HTTP requests to arbitrary endpoints during podcast episode creation.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-wvwc-5cjj-52f5

около 2 месяцев назад

PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Attackers can manipulate the 'shortdesc' parameter to trigger external HTTP requests to arbitrary endpoints during podcast episode creation.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-53899

PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Attackers can manipulate the 'shortdesc' parameter to trigger external HTTP requests to arbitrary endpoints during podcast episode creation.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-wvwc-5cjj-52f5

PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Attackers can manipulate the 'shortdesc' parameter to trigger external HTTP requests to arbitrary endpoints during podcast episode creation.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу