PT-2026-33820 · Gfi · Helpdesk
Alex Williams
+1
·
Published
2026-04-20
·
Updated
2026-04-20
·
CVE-2026-23752
CVSS v3.1
4.8
Medium
| AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the template group creation and editing functionality that allows authenticated administrators to inject arbitrary JavaScript by manipulating the companyname POST parameter without HTML sanitization. Attackers can inject malicious scripts through the companyname field that execute in the browsers of any administrator viewing the Templates > Groups page.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Helpdesk