← Volver a CVEs
CVE-2026-23753
MEDIUM4.8
Descripcion
GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the language management functionality where the charset POST parameter is passed directly to SWIFT_Language::Create() without HTML sanitization and subsequently rendered unsanitized by View_Language.RenderGrid(). An authenticated administrator can inject arbitrary JavaScript through the charset field when creating or editing a language, and the payload executes in the browser of any administrator viewing the Languages page.
Detalles CVE
Puntuacion CVSS v3.14.8
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosHIGH
Interaccion usuarioREQUIRED
Publicado4/20/2026
Ultima modificacion4/20/2026
Fuentenvd
Avistamientos honeypot0
Debilidades (CWE)
CWE-79
Referencias
https://gfi.ai/products-and-solutions/email-and-messaging-solutions/helpdesk/resources/product-releases(disclosure@vulncheck.com)
https://www.vulncheck.com/advisories/gfi-helpdesk-stored-xss-via-charset-parameter(disclosure@vulncheck.com)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.