PT-2026-81867 · Gazellepw · Gazellepw

·

CVE-2026-38465

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GazellePW (GazellePosterWall) versions prior to commit 86c4bedf727691b5a97af42a4864869d18446449
Description A Stored Cross-Site Scripting (XSS) issue exists in the donor avatar mouse-over text feature. Remote authenticated users can inject arbitrary JavaScript through the avatar mouse over text parameter. This malicious script is stored on the server and subsequently executed when the avatar tooltip is rendered for other users.
Recommendations Update GazellePW (GazellePosterWall) to commit 86c4bedf727691b5a97af42a4864869d18446449 or a newer version. As a temporary mitigation, restrict the use of the avatar mouse over text parameter.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-38465

Affected Products

Gazellepw