PowerPress Podcasting plugin by Blubrry - XML injection (XXE)
Severity pending
Summary
Full name
PowerPress Podcasting plugin by Blubrry 11.10. - XML injection (XXE)
Code name
State
Private
Release date
Jan 3, 2025
Affected product
PowerPress Podcasting plugin by Blubrry
Affected version(s)
Version 11.10.
Vulnerability name
XML injection (XXE)
Vulnerability type
Remotely exploitable
No
CVSS v4.0 vector string
CVSS:4.0/AV:N/AT:N/AC:L/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U
Exploit available
No
CVE ID(s)
Description
PowerPress Podcasting plugin by Blubrry 11.10. was found to be vulnerable. Access to external entities in XML parsing is enabled in myapp/getid3/getid3.lib.php.
Vulnerability
Skims by Fluid Attacks discovered a XML injection (XXE) in PowerPress Podcasting plugin by Blubrry 11.10.. The following is the output of the tool:
Skims output
Our security policy
We have reserved the ID CVE-2025-0775 to refer to this issue from now on.
System Information
Version: PowerPress Podcasting plugin by Blubrry 11.10.
Mitigation
There is currently no patch available for this vulnerability.
Timeline
Vulnerability discovered
Jan 3, 2025
Vendor contacted
Jan 3, 2025