Vulnerability Description
Podcast Generator 3.1 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unfiltered JavaScript code in the long_description parameter. Attackers can inject script tags through episode creation or editing requests to execute arbitrary JavaScript when other users view the episode details.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://podcastgenerator.net/demoV2/
- https://podcastgenerator.net/download
- https://www.exploit-db.com/exploits/49866
- https://www.vulncheck.com/advisories/podcast-generator-persistent-cross-site-scr
FAQ
What is CVE-2021-47968?
CVE-2021-47968 is a vulnerability with a CVSS score of 6.4 (MEDIUM). Podcast Generator 3.1 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unfiltered JavaScript code in the long_desc...
How severe is CVE-2021-47968?
CVE-2021-47968 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-47968?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.