CVE-2025-70849
EUVD-2025-20669703.02.2026, 18:16
Arbitrary File Upload in podinfo thru 6.9.0 allows unauthenticated attackers to upload arbitrary files via crafted POST request to the /store endpoint. The application renders uploaded content without a restrictive Content-Security-Policy (CSP) or adequate Content-Type validation, leading to Stored Cross-Site Scripting (XSS).
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| stefanprodan | podinfo | 𝑥 ≤ 6.9.0 |
𝑥
= Vulnerable software versions