PT-2026-33822 · Gfi · Gfi Helpdesk

Alex Williams

+1

·

Published

2026-04-20

·

Updated

2026-04-21

·

CVE-2026-23757

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GFI HelpDesk versions prior to 4.99.10
Description A stored cross-site scripting issue exists in the Reports module. The title parameter is passed directly to the SWIFT Report::Create() function without HTML sanitization. This allows attackers to inject arbitrary JavaScript into the report title field during the creation or editing of a report. The injected payload executes when staff members view and click the affected report link within the Manage Reports interface.
Recommendations Update to version 4.99.10 or later. As a temporary workaround, restrict access to the Reports module or avoid using the title parameter in the affected interface until the update is applied.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-23757

Affected Products

Gfi Helpdesk