Impact
GFI Archiver before 15.13 has a stored cross‑site scripting flaw in its Retention Policy configuration. An authenticated attacker can enter arbitrary JavaScript or HTML into the policy name field on /Archiver/RetentionPolicyWizard.aspx. The input is saved without output encoding and is later rendered when users view the Retention and Spam Policies page, allowing the attacker to execute client‑side code in those users’ browsers. The vulnerability is classified as CWE‑79.
Affected Systems
The affected product is GFI Archiver from GFI Software. Any installation that has a version older than 15.13 is vulnerable. The CNA does not list sub‑version data, so all releases prior to 15.13 should be assessed as at risk.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, and an EPSS score of less than 1% suggests a low likelihood of exploitation. The flaw requires authentication with permissions to create or edit retention policies, limiting attacker access to privileged users. It is not in the CISA KEV catalog. Because the attack vector is authenticated stored XSS, the primary danger is to any user who subsequently views the policies page, which could lead to session hijacking, cookie theft, or defacement.
OpenCVE Enrichment