Impact
GFI Archiver versions before 15.13 contain a stored cross‑site scripting flaw in the General Settings SMTP configuration. An authenticated user can submit a malicious value for the SMTP server address to /Archiver/GeneralSettingsWizard.aspx; the application saves this value without sanitization. When any user subsequently opens the General Settings page, the stored payload is rendered and executed in the browser, allowing the attacker to run arbitrary script on the client side.
Affected Systems
All releases of GFI Software’s GFI Archiver older than version 15.13 are affected. Any user who can log into the portal and modify the General Settings can trigger the vulnerability.
Risk and Exploitability
The CVSS score of 5.1 places the issue in the medium range and reflects the requirement for authentication. Exploitation involves submitting a crafted SMTP server address string; the payload is stored and later executed when other authenticated users view the General Settings page. The EPSS score of less than 1% indicates a low likelihood of real‑world exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The attack path requires that the attacker have an authenticated session within the Archiver portal and the ability to modify the SMTP server address field.
OpenCVE Enrichment