Description
GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report configuration that allows authenticated attackers to inject arbitrary web script or HTML via the report name parameter to /Archiver/MailInsights.aspx. The injected payload is stored by ReportScheduling.btnSaveReport_Click() without output encoding and is executed in the browser of the user who created the scheduled report when they subsequently view the MailInsights page.
Published: 2026-07-23
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

GFI Archiver versions before 15.13 contain a stored cross‑site scripting flaw in the MailInsights scheduled report configuration. An authenticated attacker can inject arbitrary web script or HTML into the report name field. The payload is stored by ReportScheduling.btnSaveReport_Click() without output encoding, and it is executed in the browsers of users who later view the MailInsights page, allowing client‑side code execution.

Affected Systems

All GFI Archiver releases earlier than 15.13 are affected. Users running GFI Software’s GFI Archiver below 15.13 are impacted. No other vendors or product versions are listed as affected.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity. The EPSS score of less than 1% suggests that exploitation attempts are currently uncommon. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog, further reducing its likelihood of widespread exploitation. Successful exploitation requires the attacker to be authenticated within the Archiver environment, create a malicious scheduled report, and have the report later viewed by a user in the same environment.

Generated by OpenCVE AI on August 3, 2026 at 21:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade GFI Archiver to version 15.13 or newer.
  • Disable or remove the MailInsights feature if it is not required.
  • Restrict permissions for creating scheduled reports or enforce input validation and output encoding on the report name field.

Generated by OpenCVE AI on August 3, 2026 at 21:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Gfi
Gfi archiver
CPEs cpe:2.3:a:gfi:archiver:*:*:*:*:*:*:*:*
Vendors & Products Gfi
Gfi archiver

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Gfi Software
Gfi Software gfi Archiver
Vendors & Products Gfi Software
Gfi Software gfi Archiver
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report configuration that allows authenticated attackers to inject arbitrary web script or HTML via the report name parameter to /Archiver/MailInsights.aspx. The injected payload is stored by ReportScheduling.btnSaveReport_Click() without output encoding and is executed in the browser of the user who created the scheduled report when they subsequently view the MailInsights page.
Title GFI Archiver < 15.13 Stored XSS via MailInsights.aspx
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Gfi Archiver
Gfi Software Gfi Archiver
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-28T01:49:30.714Z

Reserved: 2026-05-21T18:34:46.417Z

Link: CVE-2026-48539

cve-icon Vulnrichment

Updated: 2026-07-23T15:39:37.529Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T16:17:26.470

Modified: 2026-07-23T17:55:03.860

Link: CVE-2026-48539

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T21:30:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')