PT-2026-33821 · Gfi · Helpdesk
Alex Williams
+1
·
Published
2026-04-20
·
Updated
2026-04-20
·
CVE-2026-23753
CVSS v3.1
4.8
Medium
| AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the language management functionality where the charset POST parameter is passed directly to SWIFT Language::Create() without HTML sanitization and subsequently rendered unsanitized by View Language.RenderGrid(). An authenticated administrator can inject arbitrary JavaScript through the charset field when creating or editing a language, and the payload executes in the browser of any administrator viewing the Languages page.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Helpdesk