PT-2026-81854 · Gazellepw · Gazellepw

·

CVE-2026-38467

·

Published

2026-08-25

·

Updated

2026-08-31

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GazellePW (GazellePosterWall) versions prior to commit 86c4bedf727691b5a97af42a4864869d18446449
Description A SQL injection issue exists in the tags manager. Remote authenticated users with users mod privileges can execute arbitrary SQL commands by sending a crafted POST request to the 'tools.php?action=manage tags' endpoint using the tagid or type parameters.
Recommendations Update GazellePW (GazellePosterWall) to a version including commit 86c4bedf727691b5a97af42a4864869d18446449 or later. As a temporary mitigation, restrict access to the 'tools.php?action=manage tags' endpoint or avoid using the tagid and type parameters until the update is applied.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-38467

Affected Products

Gazellepw