Impact
A stored Cross‑Site Scripting flaw resides in the remaster custom title feature of GazellePosterWall. The remaster_custom_title parameter is saved when a torrent is uploaded or edited and later rendered in the torrent title output without proper sanitization. An authenticated user who can add or edit torrents can supply any JavaScript payload that will execute in the context of any browser that loads the affected torrent title, leading to potential theft of session data, credential compromise, or execution of malicious code.
Affected Systems
The vulnerability affects installations of GazellePosterWall (GazellePW) that include commit 86c4bedf727691b5a97af42a4864869d18446449 or later builds that have not applied the correct input validation changes. End‑users and administrators running versions of GazellePW that expose the remaster custom title input are at risk.
Risk and Exploitability
Exploit requires only that an attacker possess the privilege to create or modify a torrent entry, a privilege often granted to authenticated community members. Once a payload is stored, every visitor who views the torrent with the malicious title will have the script executed. The CVSS score of 5.4 indicates a moderate severity, while the EPSS score remains less than 1% and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless the nature of a stored XSS that propagates to all viewers presents a significant confidentiality and integrity risk for the victim community. The attack vector is remote authenticated and the conditions for exploitation are readily met on any functional GazellePW instance without additional environmental constraints.
OpenCVE Enrichment