Impact
GFI Archiver versions before 15.13 contain a stored cross-site scripting flaw in the File Archive Assistant configuration page. An authenticated user can inject JavaScript or HTML into the "excluded extensions" field of /Archiver/FileArchiveAssistantWizard.aspx. The injected payload is stored without output encoding and is executed in the browsers of users who subsequently view the File Archive Assistant settings page, allowing attackers to run arbitrary code in the context of authenticated users and potentially enabling session hijacking, credential theft, or UI defacement.
Affected Systems
The vulnerability affects all deployments of GFI Software’s GFI Archiver running a release earlier than version 15.13. No further version granularity is available in the CVE data, so any installation of 15.12 or below that has not applied a patch is at risk.
Risk and Exploitability
The CVSS score of 5.1 classifies the issue as moderate severity. The very low EPSS score (< 1 %) indicates a limited likelihood of current exploitation, and the flaw is not listed in CISA’s KEV catalog. Exploitation requires an authenticated account with sufficient privileges to access the File Archive Assistant configuration. After injection, the payload persists and will automatically execute for any user who later views the settings page, thereby amplifying the impact.
OpenCVE Enrichment