Beveiligingsadvies

CVE-2025-70336

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-01-28 00:00:00
Laatst bijgewerkt 2026-01-29 17:12:29
Toegewezen door mitre
CVSS-score 4.8
Status PUBLISHED

Beschrijving

A Stored cross-site scripting (XSS) vulnerability in 'Create New Live Item' in PodcastGenerator 3.2.9 allows remote attackers to inject arbitrary script or HTML via the 'TITLE', 'SHORT DESCRIPTION' and 'LONG DESCRIPTION' parameters. The saved payload gets executed on 'View All Live Items' and 'Live Stream' pages.