Description
PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the Freebox content field accessible through the theme customization interface (theme_freebox.php). Malicious JavaScript payloads injected into the Freebox content execute when users visit the application's home page.
Remediation
References
Related Vulnerabilities
Next.js User Interface (UI) Misrepresentation of Critical Information Vulnerability (CVE-2022-23646)
Liferay Portal CVE-2020-15840 Vulnerability (CVE-2020-15840)
WordPress Plugin WP Auctions 'wpa_id' Parameter SQL Injection (1.8.8)
Apache Tomcat Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-1582)