Impact
The vulnerability allows authenticated users to inject arbitrary JavaScript or HTML into the CallHomeSettingsWizard page. The input is accepted by the proxy server address field, saved without encoding, and executed when other users view the General Settings Additional Settings page. This can lead to malicious scripts running in the browsers of legitimate users, potentially compromising their credentials or session data.
Affected Systems
All installations of GFI Archiver running a version earlier than 15.13 are vulnerable. The flaw resides in the Call Home proxy server configuration interface provided by GFI Software.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate threat, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker needs authenticated access to the Archiver web console and must submit a crafted proxy address. Once the payload is stored, it is delivered to any user who views the affected settings page. Attackers could hijack user sessions or steal credentials by executing client‑side scripts.
OpenCVE Enrichment