CVE-2026-23758

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows authenticated staff members to inject malicious JavaScript by manipulating the editsubject POST parameter. Attackers can inject XSS payloads through inadequate sanitization in Controller_Ticket.EditSubmit() that bypass the incomplete SanitizeForXSS() method to execute arbitrary JavaScript when other staff members or administrators view the affected ticket.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gfi:helpdesk:*:*:*:*:*:*:*:*

History

27 Apr 2026, 14:58

Type Values Removed Values Added
References () https://gfi.ai/products-and-solutions/email-and-messaging-solutions/helpdesk/resources/product-releases - () https://gfi.ai/products-and-solutions/email-and-messaging-solutions/helpdesk/resources/product-releases - Release Notes
References () https://www.vulncheck.com/advisories/gfi-helpdesk-stored-xss-via-editsubject-parameter - () https://www.vulncheck.com/advisories/gfi-helpdesk-stored-xss-via-editsubject-parameter - Third Party Advisory
CPE cpe:2.3:a:gfi:helpdesk:*:*:*:*:*:*:*:*
First Time Gfi
Gfi helpdesk
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

20 Apr 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-20 18:16

Updated : 2026-04-27 14:58


NVD link : CVE-2026-23758

Mitre link : CVE-2026-23758

CVE.ORG link : CVE-2026-23758


JSON object : View

Products Affected

gfi

  • helpdesk
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')