Impact
GFI Archiver versions before 15.13 contain a stored cross‑site scripting flaw in the MailInsights scheduled report configuration. An authenticated attacker can inject arbitrary web script or HTML into the report name field. The payload is stored by ReportScheduling.btnSaveReport_Click() without output encoding, and it is executed in the browsers of users who later view the MailInsights page, allowing client‑side code execution.
Affected Systems
All GFI Archiver releases earlier than 15.13 are affected. Users running GFI Software’s GFI Archiver below 15.13 are impacted. No other vendors or product versions are listed as affected.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score of less than 1% suggests that exploitation attempts are currently uncommon. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog, further reducing its likelihood of widespread exploitation. Successful exploitation requires the attacker to be authenticated within the Archiver environment, create a malicious scheduled report, and have the report later viewed by a user in the same environment.
OpenCVE Enrichment