Executive brief
GazellePW is a web application used to manage torrent tracker communities. A SQL injection vulnerability in the country-code lookup feature allows authenticated users with IP-viewing privileges to execute arbitrary database queries, potentially exposing or modifying sensitive user data or tracker configuration.
Technical details
The vulnerability is a SQL injection flaw in the get_cc.php endpoint (tools.php?action=get_cc) that processes the 'ip' parameter unsafely. The Tools::geoip() function in tools.class.php does not properly sanitize or parameterize the $_GET['ip'] input before passing it to a database query, allowing an authenticated user with the 'users_view_ips' permission to inject arbitrary SQL. Attack requires authentication and the specific privilege grant, but no additional user interaction. An attacker can execute SELECT, UPDATE, or DELETE queries depending on database configuration, potentially exfiltrating user records, modifying tracker data, or gaining further system access. No patch information is publicly available at this time.
Affected products
- GazellePW GazellePW commit 86c4bedf727691b5a97af42a4864869d18446449
Timeline
- 2026-08-25: disclosed