PT-2026-81867 · Gazellepw · Gazellepw
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GazellePW (GazellePosterWall) versions prior to commit 86c4bedf727691b5a97af42a4864869d18446449
Description
A Stored Cross-Site Scripting (XSS) issue exists in the donor avatar mouse-over text feature. Remote authenticated users can inject arbitrary JavaScript through the
avatar mouse over text parameter. This malicious script is stored on the server and subsequently executed when the avatar tooltip is rendered for other users.Recommendations
Update GazellePW (GazellePosterWall) to commit 86c4bedf727691b5a97af42a4864869d18446449 or a newer version.
As a temporary mitigation, restrict the use of the
avatar mouse over text parameter.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gazellepw