Metrics
Affected Vendors & Products
Mon, 20 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV4_0
|
cvssV4_0
|
Mon, 20 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows authenticated staff members to inject malicious JavaScript by manipulating the editsubject POST parameter. Attackers can inject XSS payloads through inadequate sanitization in Controller_Ticket.EditSubmit() that bypass the incomplete SanitizeForXSS() method to execute arbitrary JavaScript when other staff members or administrators view the affected ticket. | |
| Title | GFI HelpDesk < 4.99.9 Stored XSS via editsubject Parameter | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-20T17:45:55.788Z
Reserved: 2026-01-15T18:42:20.938Z
Link: CVE-2026-23758
Updated: 2026-04-20T17:45:52.114Z
Status : Awaiting Analysis
Published: 2026-04-20T18:16:24.643
Modified: 2026-04-20T19:05:30.750
Link: CVE-2026-23758
No data.
OpenCVE Enrichment
No data.