CVE-2026-23758

GFI HelpDesk beforeĀ 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows authenticated staff members to inject malicious JavaScript by manipulating the editsubject POST parameter. Attackers can inject XSS payloads through inadequate sanitization in Controller_Ticket.EditSubmit() that bypass the incomplete SanitizeForXSS() method to execute arbitrary JavaScript when other staff members or administrators view the affected ticket.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gfi:helpdesk:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-20 18:16

Updated : 2026-06-17 10:22


NVD link : CVE-2026-23758

Mitre link : CVE-2026-23758

CVE.ORG link : CVE-2026-23758


JSON object : View

Products Affected

gfi

  • helpdesk
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')