CVE-2017-7247 describes multiple Cross-Site Scripting (XSS) vulnerabilities in Gazelle before the 2017-03-19 release. These flaws stem from insufficient sanitization of user-supplied data, specifically in torrent and size parameters, when processed by the 'multiple_freeleech.php' URL. An attacker could exploit this to inject and execute arbitrary HTML or script code within a victim's browser in the context of the vulnerable website, leading to potential information disclosure or session hijacking. Rated 6.1 MEDIUM on the CVSS scale, this vulnerability requires user interaction (UI:R) and has a network attack vector (AV:N) with low impact on confidentiality and integrity. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2016-11-01CPE matchmatch criteria | cpe:2.3:a:gazelle_project:gazelle:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.