PT-2026-81868 · Gazellepw · Gazellepw
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GazellePW (GazellePosterWall) versions prior to commit 86c4bedf727691b5a97af42a4864869d18446449
Description
A Stored Cross-Site Scripting (XSS) issue exists in the torrent remaster custom title feature. Remote authenticated users can inject arbitrary JavaScript through the
remaster custom title parameter. This script is stored during the torrent upload or edit process and is subsequently executed when the torrent title is rendered in the output.Recommendations
Update GazellePW (GazellePosterWall) to commit 86c4bedf727691b5a97af42a4864869d18446449 or a newer version.
As a temporary mitigation, restrict the use of the
remaster custom title parameter during torrent upload and editing.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gazellepw