---
id: CVE-2023-53899
title: >-
  PodcastGenerator 3.2.9 contains a blind server-side request forgery
  vulnerability that allows attackers to inject XML in the episode upload form
summary: >-
  PodcastGenerator 3.2.9 contains a blind server-side request forgery
  vulnerability that allows attackers to inject XML in the episode upload form.
  Attackers can manipulate the 'shortdesc' parameter to trigger external HTTP
  requests to arb…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-918
vendor: podcastgenerator
product: podcast_generator
affected:
  - podcast_generator = 3.2.9
published: '2025-12-16'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T18:17:52.817'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-53899'
references:
  - url: 'https://github.com/PodcastGenerator/PodcastGenerator'
    label: disclosure@vulncheck.com
  - url: 'https://podcastgenerator.net/'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/51565'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/podcastgenerator-blind-server-side-request-forgery-via-xml-injection
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00571
epssPercentile: 0.45134
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2025-12-16T21:42:27.212367Z'
ingestedAt: '2026-09-30T18:17:24.568Z'
---

## Overview

PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Attackers can manipulate the 'shortdesc' parameter to trigger external HTTP requests to arbitrary endpoints during podcast episode creation.

## Affected

- `podcast_generator = 3.2.9`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
