Stored XSS Vulnerability in PodcastGenerator Affects User Safety
CVE-2025-70336
4.8MEDIUM
What is CVE-2025-70336?
A Stored Cross-Site Scripting (XSS) vulnerability exists in the 'Create New Live Item' feature of PodcastGenerator 3.2.9. This flaw permits remote attackers to inject arbitrary JavaScript code or HTML through the 'TITLE', 'SHORT DESCRIPTION', and 'LONG DESCRIPTION' fields. Once exploited, the malicious payload can execute on the 'View All Live Items' and 'Live Stream' pages, potentially compromising the integrity and security of the user’s data and experience. Stakeholders are urged to apply security patches or updates to mitigate this risk.
