Description
GFI HelpDesk beforeĀ 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows authenticated staff members to inject malicious JavaScript by manipulating the editsubject POST parameter. Attackers can inject XSS payloads through inadequate sanitization in Controller_Ticket.EditSubmit() that bypass the incomplete SanitizeForXSS() method to execute arbitrary JavaScript when other staff members or administrators view the affected ticket.
INFO
Published Date :
2026-04-20T17:30:06.853Z
Last Modified :
2026-04-20T17:45:55.788Z
Source :
VulnCheck
AFFECTED PRODUCTS
The following products are affected by CVE-2026-23758 vulnerability.
| Vendors | Products |
|---|---|
| Gfi |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-23758.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
VS Confidentiality
VS Integrity
VS Availability
SS Confidentiality
SS Integrity
SS Availability