PT-2026-33815 · Gfi · Gfi Helpdesk

Alex Williams

+1

·

Published

2026-04-20

·

Updated

2026-04-21

·

CVE-2026-23758

CVSS v4.0

6.4

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions GFI HelpDesk versions prior to 4.99.9
Description A stored cross-site scripting issue exists in the ticket subject field. Authenticated staff members can inject malicious JavaScript by manipulating the 'editsubject' POST parameter. This occurs due to inadequate sanitization in the Controller Ticket.EditSubmit() function, which bypasses the incomplete SanitizeForXSS() method, allowing arbitrary JavaScript execution when other staff members or administrators view the affected ticket.
Recommendations Update to version 4.99.9 or later. As a temporary workaround, restrict access to the Controller Ticket.EditSubmit() function or the 'editsubject' parameter to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-23758

Affected Products

Gfi Helpdesk