GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 suffers from a Broken access control vulnerability in the IP lock manager, which allows remote authenticated users to add, modify, or delete IP lock entries for arbitrary accounts via tools.php?action=iplock.
Metrics
Affected Vendors & Products
References
History
Mon, 31 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Broken access control in GazellePW IP lock manager enables remote authenticated modifications | Broken Access Control in GazellePosterWall IP Lock Manager Enables Unauthorized Modification |
Mon, 31 Aug 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Broken access control in GazellePW IP lock manager enables remote authenticated modifications |
Mon, 31 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated Users Can Alter IP Lock Entries in GazellePosterWall, Enabling Access Control Bypass | |
| Weaknesses | CWE-285 |
Mon, 31 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 26 Aug 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated Users Can Alter IP Lock Entries in GazellePosterWall, Enabling Access Control Bypass | |
| Weaknesses | CWE-284 CWE-285 |
Tue, 25 Aug 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 suffers from a Broken access control vulnerability in the IP lock manager, which allows remote authenticated users to add, modify, or delete IP lock entries for arbitrary accounts via tools.php?action=iplock. | |
| References |
|
|
Status: PUBLISHED
Assigner: mitre
Published: 2026-08-25T00:00:00.000Z
Updated: 2026-08-31T15:17:49.485Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-38474
Updated: 2026-08-31T15:17:38.056Z
Status : Deferred
Published: 2026-08-25T22:17:04.037
Modified: 2026-08-31T16:17:59.170
Link: CVE-2026-38474
No data.