Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-38467

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 GazellePW(GazellePosterWall)的提交 86c4bedf727691b5a97af42a4864869d18446449 中,标签管理器(tags manager)存在一个 SQL 注入漏洞。具有 users_mod 权限的远程认证用户可以通过向 tools.php?action=manage_tags 发送精心构造的 POST 请求,利用 tagid 或 type 参数执行任意 SQL 命令。

AI Predicted 8.8 Difficulty: Easy

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-38467

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A SQL injection vulnerability in the tags manager in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users with users_mod privileges to execute arbitrary SQL commands via the tagid or type parameter in a crafted POST request to tools.php?action=manage_tags.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-38467

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-38467

登录查看更多情报信息。

Exploits & Public PoCs for CVE-2026-38467 (1)

Other References for CVE-2026-38467 (1)

Same Patch Batch · n/a · 2026-08-25 · 15 CVEs total

CVE-2026-75465 Maccms v10越权漏洞:敏感信息泄露
CVE-2026-75421 aria2<=1.37.0 IOFile::getLine函数栈缓冲区下溢漏洞
CVE-2026-52489 gpac缓冲区溢出漏洞
CVE-2026-52491 libtiff远程代码执行漏洞
CVE-2026-38468 GazellePW 任意代码执行漏洞
CVE-2026-51368 TongWeb v.7.0.24代码执行漏洞
CVE-2026-39113 SQLite < 2026-03-11 快照存在缓冲区溢出致DoS漏洞
CVE-2026-38466 GazellePW存储型XSS漏洞
CVE-2026-38465 GazellePW存储型XSS漏洞
CVE-2026-38469 GazellePW存储型XSS漏洞
CVE-2026-38474 GazellePW IP锁管理器存在越权漏洞
CVE-2026-38473 GazellePW存储型XSS漏洞
CVE-2026-38472 GazellePW存储型XSS漏洞
CVE-2026-38470 GazellePW API越权漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-38467

No comments yet


Leave a comment