What the vulnerability does
01Description
Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.14.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
What the vulnerability does
Missing Authorization vulnerability in Podlove Podlove Podcast Publisher.This issue affects Podlove Podcast Publisher: from n/a through 4.0.14.
Explanation of Vulnerability in Simple Terms
Podlove Podcast Publisher versions up to 4.0.14 lack proper authorization checks, allowing unauthenticated attackers to disrupt podcast availability. An attacker can send requests over the network without authentication to trigger a denial-of-service condition. Site administrators running affected versions should update immediately to restore service stability.
What an attacker can do
Make the site unavailable or unresponsive by sending network requests without logging in.
Potential impact on your site
Podcast feeds and player functionality may become unavailable to listeners without warning.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities