PT-2026-33814 · Gfi · Helpdesk

Alex Williams

+1

·

Published

2026-04-20

·

Updated

2026-04-20

·

CVE-2026-23756

CVSS v3.1

5.4

Medium

AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the subject POST parameter is not sanitized in Controller Step.InsertSubmit() and EditSubmit() before being rendered by View Step.RenderViewSteps(). An authenticated staff member can inject arbitrary JavaScript into the step subject field, and the payload executes when any user navigates to Troubleshooter > View Troubleshooter and clicks the affected step link.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-23756

Affected Products

Helpdesk