Impact
A source‑directed SQL injection flaw exists in the country‑code lookup endpoint of GazellePosterWall. By manipulating the ip parameter in a request to tools.php?action=get_cc, an attacker who can authenticate and holds the users_view_ips privilege can execute any SQL statement against the database. This can expose, alter, or delete data, and if the database is exposed system commands may become available as well. The impact is limited to the database layer but can lead to full compromise of the application data store.
Affected Systems
GazellePosterWall (GazellePW) at git commit 86c4bedf727691b5a97af42a4864869d18446449. No other vendors or versions are listed.
Risk and Exploitability
The CVE is not in the CISA KEV catalog and the EPSS score is less than 1%, indicating a low probability of exploitation. Because the flaw requires authentication with users_view_ips rights, the attack surface is smaller than a public injection. However, once an authenticated user abuses the vulnerability, any SQL command can be run, making the risk high for data confidentiality and integrity. The CVSS score is 4.3, reflecting a moderate impact.
OpenCVE Enrichment