CVE-2021-32772
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in helper_entries
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Poddycast is a podcast app made with Electron. Prior to version 0.8.1, an attacker can create a podcast or episode with malicious characters and execute commands on the client machine. The application does not clean the HTML characters of the podcast information obtained from the Feed, which allows the injection of HTML and JS code (cross-site scripting). Being an application made in electron, cross-site scripting can be scaled to remote code execution, making it possible to execute commands on the machine where the application is running. The vulnerability is patched in Poddycast version 0.8.1.
Poddycast es una aplicación de podcast hecha con Electron. Anterior a versión 0.8.1, un atacante puede crear un podcast o episodio con caracteres maliciosos y ejecutar comandos en la máquina cliente. La aplicación no limpia los caracteres HTML de la información del podcast obtenida del Feed, lo que permite la inyección de código HTML y JS (cross-site scripting). Al tratarse de una aplicación realizada en electron, el ataque de tipo cross-site scripting puede escalar a la ejecución de código remota, haciendo posible la ejecución de comandos en la máquina donde se ejecuta la aplicación. La vulnerabilidad está parcheada en la versión 0.8.1 de Poddycast
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-05-12 CVE Reserved
- 2021-08-03 CVE Published
- 2024-04-18 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (4)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Electronjs Search vendor "Electronjs" | Poddycast Search vendor "Electronjs" for product "Poddycast" | 0.8.0 Search vendor "Electronjs" for product "Poddycast" and version "0.8.0" | - |
Affected
|