Code Injection Vulnerability in Podlove Podcast Publisher
CVE-2024-43984
9.6CRITICAL
Summary
A Cross-Site Request Forgery (CSRF) vulnerability found in Podlove Podcast Publisher allows malicious actors to perform code injection attacks. This security flaw affects versions of the Podlove Podcast Publisher up to and including 4.1.13, enabling unauthorized actions without proper user authentication. Websites utilizing this plugin may be at risk, allowing attackers to execute arbitrary code and potentially compromising the integrity of the system.
Affected Version(s)
Podlove Podcast Publisher <= 4.1.13
References
CVSS V3.1
Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Credit
Muhammad Daffa (Patchstack Alliance)