Impact
A stored cross‑site scripting flaw exists in the custom bonus title feature of GazellePosterWall (commit 86c4bedf727691b5a97af42a4864869d18446449). Authenticated users with sufficient privileges can inject arbitrary JavaScript by submitting a specially crafted value for the title parameter in /bonus.php and /user.php?action=staff_tool. When a victim visits the affected bonus page, the injected script executes within their browser session, allowing the attacker to steal session cookies, hijack their account, deface the page, or deliver malware. The weakness is a classic CWE‑79 input validation issue.
Affected Systems
The vulnerability affects instances of GazellePosterWall (GazellePW) running the code from commit 86c4bedf727691b5a97af42a4864869d18446449. No vendor name is provided in the advisory, and the product is a community‑maintained forum application. Any installation that has not been upgraded past that commit is potentially exploitable.
Risk and Exploitability
The CVSS score of 5.4 classifies the flaw as a moderate risk. The EPSS score is less than 1%, indicating a low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user capable of editing bonus titles; no remote unauthenticated exploit is described. Once exploited, it grants the attacker the ability to run arbitrary code in the context of any user who views the affected page.
OpenCVE Enrichment