Executive brief
Podcast Generator, an open-source content management system for publishing podcasts, is vulnerable to a security flaw where an attacker can inject malicious scripts into episode descriptions. If an authorized user (such as a contributor) saves a specially crafted description, the malicious code will run in the browser of any other user or administrator who views that episode. This could lead to unauthorized actions being performed on behalf of other users or the theft of sensitive session information.
Technical details
A persistent cross-site scripting (XSS) vulnerability exists in Podcast Generator versions prior to 3.1.1. The root cause is the improper neutralization of user-supplied input within the 'long_description' POST parameter during episode creation or editing. An authenticated attacker with permissions to modify episodes can inject arbitrary JavaScript via <script> tags. Because the application fails to filter this input, the payload is stored in the database and executed in the security context of any user who subsequently views the episode details page. This can be used to hijack sessions or perform unauthorized administrative actions. The issue is addressed in version 3.1.1.
Affected products
- Podcast Generator Podcast Generator < 3.1.1
Timeline
- 2021-05-13: disclosed: Initial exploit discovery and PoC authoring
- 2021-05-14: other: Exploit published on Exploit-DB
- 2026-05-15: advisory: NVD and VulnCheck advisory published