CyberRota Analysis
AI-GeneratedThe vulnerability affects the torrent remaster custom title feature in GazellePW, allowing remote authenticated users to exploit a Stored XSS flaw via the remaster_custom_title parameter during torrent uploads or edits. This could lead to the injection of arbitrary JavaScript, potentially compromising user sessions or executing malicious scripts in the context of other users. Organizations utilizing GazellePW should prioritize remediation to protect against potential exploitation of this vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A Stored XSS vulnerability in the torrent remaster custom title feature in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users to inject arbitrary JavaScript via the remaster_custom_title parameter, which is stored during torrent upload or edit and later rendered in torrent title output.