Impact
GFI Archiver prior to version 15.13 stores an unencoded server URL, allowing authenticated users to inject arbitrary web script that is executed the next time users view the IMAP Server configuration page. The injected payload is stored by ImapServerWizard.SaveAllConfigSettings() without output encoding and is executed in browsers of users who subsequently view the configuration page. The vulnerability has a CVSS score of 5.1, indicating a medium severity impact.
Affected Systems
The affected product is GFI Archiver from GFI Software, versions earlier than 15.13. No additional version details are supplied by the vendor.
Risk and Exploitability
The attack requires authentication to the web application to use the ImapServerWizard.aspx page. Account holders with sufficient privileges can supply a malicious URL that is stored and later rendered without encoding. The EPSS score is below 1 %, suggesting a low probability of widespread exploitation at present, and the vulnerability is not present in CISA’s KEV catalog. However, the stored nature of the flaw means that any authenticated user could trigger the payload on subsequent page views, creating a persistent cross‑site scripting risk.
OpenCVE Enrichment