Impact
A stored cross‑site scripting flaw resides in GFI Archiver’s Classification Rules configuration. Authenticated users can enter arbitrary script or HTML into the rule name and email criteria fields, and the application stores the payload without encoding it. Subsequent users who view the Classification Rules page are forced to execute the injected code in their browsers, enabling session hijacking, phishing, or defacement attacks.
Affected Systems
The vulnerability is limited to GFI Archiver versions earlier than 15.13. The affected component is the CategorizationPolicyWizard.aspx page that handles rule editing. Only users with permission to configure classification rules can exploit the flaw.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The flaw is not listed in CISA’s KEV catalog, so no widespread attacks are documented. Exploitation requires an attacker to first authenticate to the Archiver system and then create a rule containing malicious script; the injected code will execute whenever another authorized user opens the rule configuration view.
OpenCVE Enrichment