Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-38474

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GazellePW(GazellePosterWall)在提交 86c4bedf727691b5a97af42a4864869d18446449 中存在一个损坏的访问控制漏洞,位于 IP 锁定管理器中,允许远程认证用户通过 tools.php?action=iplock 为任意账户添加、修改或删除 IP 锁定条目。

AI Predicted 9.8 Difficulty: Easy

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-38474

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 suffers from a Broken access control vulnerability in the IP lock manager, which allows remote authenticated users to add, modify, or delete IP lock entries for arbitrary accounts via tools.php?action=iplock.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2026-38474

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-38474

登录查看更多情报信息。

Patches & Fixes for CVE-2026-38474 (2)

Exploits & Public PoCs for CVE-2026-38474 (1)

Proof of Concept for CVE-2026-38474 (1)

Same Patch Batch · n/a · 2026-08-25 · 15 CVEs total

CVE-2026-75465 Maccms v10越权漏洞:敏感信息泄露
CVE-2026-75421 aria2<=1.37.0 IOFile::getLine函数栈缓冲区下溢漏洞
CVE-2026-52489 gpac缓冲区溢出漏洞
CVE-2026-52491 libtiff远程代码执行漏洞
CVE-2026-38467 GazellePW标签管理器存在SQL注入漏洞
CVE-2026-38468 GazellePW 任意代码执行漏洞
CVE-2026-51368 TongWeb v.7.0.24代码执行漏洞
CVE-2026-39113 SQLite < 2026-03-11 快照存在缓冲区溢出致DoS漏洞
CVE-2026-38466 GazellePW存储型XSS漏洞
CVE-2026-38465 GazellePW存储型XSS漏洞
CVE-2026-38469 GazellePW存储型XSS漏洞
CVE-2026-38473 GazellePW存储型XSS漏洞
CVE-2026-38472 GazellePW存储型XSS漏洞
CVE-2026-38470 GazellePW API越权漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-38474

No comments yet


Leave a comment