What the vulnerability does
01Description
Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.1.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.1.0.
Explanation of Vulnerability in Simple Terms
Podlove Podcast Publisher through version 4.1.0 lacks proper authorization checks, allowing authenticated users to modify podcast data they should not have access to. An attacker with a low-privilege account can alter podcast settings or content without proper permission validation. The vulnerability affects the integrity of podcast information but does not expose sensitive data or disrupt availability.
What an attacker can do
Modify podcast data or settings without proper authorization.
Potential impact on your site
Podcast content or settings could be altered by unauthorized users with site access.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the site.
Key dates
External resources
Related vulnerabilities