Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
PodcastGenerator 3.2.9 Blind Server-Side Request Forgery via XML Injection
Vulnerability Description
PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Attackers can manipulate the 'shortdesc' parameter to trigger external HTTP requests to arbitrary endpoints during podcast episode creation.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
Podcast Generator 安全漏洞
Vulnerability Description
Podcast Generator是PodcastGenerator开源的一套使用PHP语言编写的免费播客发布脚本。 Podcast Generator 3.2.9版本存在安全漏洞,该漏洞源于盲服务器端请求伪造,可能导致攻击者在剧集上传表单中注入XML。
CVSS Information
N/A
Vulnerability Type
N/A