GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows authenticated staff members to inject malicious JavaScript by manipulating the editsubject POST parameter. Attackers can inject XSS payloads through inadequate sanitization in Controller_Ticket.EditSubmit() that bypass the incomplete SanitizeForXSS() method to execute arbitrary JavaScript when other staff members or administrators view the affected ticket.
References
| Link | Resource |
|---|---|
| https://gfi.ai/products-and-solutions/email-and-messaging-solutions/helpdesk/resources/product-releases | Release Notes |
| https://www.vulncheck.com/advisories/gfi-helpdesk-stored-xss-via-editsubject-parameter | Third Party Advisory |
Configurations
History
27 Apr 2026, 14:58
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://gfi.ai/products-and-solutions/email-and-messaging-solutions/helpdesk/resources/product-releases - Release Notes | |
| References | () https://www.vulncheck.com/advisories/gfi-helpdesk-stored-xss-via-editsubject-parameter - Third Party Advisory | |
| CPE | cpe:2.3:a:gfi:helpdesk:*:*:*:*:*:*:*:* | |
| First Time |
Gfi
Gfi helpdesk |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
20 Apr 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-20 18:16
Updated : 2026-04-27 14:58
NVD link : CVE-2026-23758
Mitre link : CVE-2026-23758
CVE.ORG link : CVE-2026-23758
JSON object : View
Products Affected
gfi
- helpdesk
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
