EIP-2026-107353

PRE-CVE

Gazelle CMS 1.0 - Update Statement SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-107353. PoCs published by hackme.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Ananta Gazelle CMS 1.0, allowing an attacker to update the admin username and password by manipulating the POST data in the forgot.php page. The exploit leverages the lack of input validation to execute arbitrary SQL UPDATE statements.

Description

Gazelle CMS 1.0 - Update Statement SQL Injection

Exploits (1)

exploitdb WORKING POC
by hackme · textwebappsphp
https://www.exploit-db.com/exploits/18470

This exploit demonstrates a SQL injection vulnerability in Ananta Gazelle CMS 1.0, allowing an attacker to update the admin username and password by manipulating the POST data in the forgot.php page. The exploit leverages the lack of input validation to execute arbitrary SQL UPDATE statements.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Ananta Gazelle CMS 1.0
No auth needed
Prerequisites: Access to the forgot.php page · Knowledge of the table structure
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026