Impact
The vulnerability is a stored cross‑site scripting flaw in GazellePW's forum reward comments. Remote attackers can submit a crafted request to /forums.php?action=ajax_get_jf with a malicious value in the c parameter. The value is persisted and later rendered inside the data-tooltip attribute on /forums.php?action=viewthread, where Tooltipster interprets the attribute as HTML. As a result, the attacker's JavaScript runs in the browser context of any user who views the thread, enabling session hijack, credential theft, defacement, or other client‑side attacks.
Affected Systems
GazellePW (GazellePosterWall) versions up to and including the commit 86c4bedf727691b5a97af42a4864869d18446449, and any earlier revisions that have not addressed the sanitization of the c parameter, are vulnerable.
Risk and Exploitability
The EPSS score is <1% and the CVSS score is 6.1, indicating moderate severity. The flaw permits remote, unauthenticated execution of arbitrary JavaScript in user browsers by sending a single HTTP request. While the exploitation probability is low, the impact on confidentiality, integrity, and availability of affected users is significant. The vulnerability is not listed in the CISA KEV catalog, but the potential for widespread client‑side compromise warrants immediate attention.
OpenCVE Enrichment