Impact
GFI Archiver before version 15.13 contains a stored cross‑site scripting flaw, which is a CWE‑79 weakness, that allows authenticated users to insert arbitrary script or HTML into the ImportSettingsWizard.ashx folders parameter. The input is saved by ImportSettingsWizard.SaveAllConfigSettings() without output encoding and is rendered unfiltered when an authenticated user views the Archive Assistant default import settings, causing the browser to execute the injected payload.
Affected Systems
This vulnerability applies to all GFI Archiver installations running a version older than 15.13, regardless of the operating system, as the flaw resides in the web interface. Administrators should compare the installed software version against the vendor’s release list to confirm exposure.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium‑impact stored XSS that requires user authentication. With an EPSS score of less than 1%, the likelihood of active exploitation is currently low, and the vulnerability is not included in CISA’s KEV catalog. Exploitability requires that an attacker obtain valid credentials, inject malicious code into the import settings store, and then have other authenticated users view those settings for the script to run.
OpenCVE Enrichment