Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-44797 1 Gazelle Project 1 Gazelle 2024-09-06 5.4 Medium
A cross-site scripting (XSS) vulnerability in the component /managers/enable_requests.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the view parameter.
CVE-2024-44793 1 Gazelle Project 1 Gazelle 2024-09-05 6.1 Medium
A cross-site scripting (XSS) vulnerability in the component /managers/multiple_freeleech.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the torrents parameter.
CVE-2024-44795 1 Gazelle Project 1 Gazelle 2024-09-05 6.1 Medium
A cross-site scripting (XSS) vulnerability in the component /login/disabled.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter.