Description
PodcastGenerator 3.2.9 contains a stored cross-site scripting vulnerability in the podcast title field accessible through the podcast details interface (podcast_details.php). Malicious JavaScript payloads injected into the podcast title execute when users visit the application's home page.
Remediation
References
Related Vulnerabilities
Drupal Core 5.x Multiple Vulnerabilities (5.0 - 5.12)
Caddy Web Server URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-29718)
Oracle JRE CVE-2020-2757 Vulnerability (CVE-2020-2757)
WordPress Plugin Page Builder:PageLayer-Drag and Drop website builder Cross-Site Scripting (1.3.4)