Junglewise Threat Intelligence

CVE-2026-48530: GFI Archiver stored XSS in Classification Rules configuration

CVE-2026-48530 · Severity: medium · CVSS 5.4 · Published 2026-07-23

Technologies: GFI Software Archiver. Vendors: GFI Software.

Executive brief

GFI Archiver, a solution used for archiving and managing corporate emails and files, is affected by a security flaw in its classification rules settings. An authorized user can inject malicious code into the system, which will then run in the browsers of other administrators who view those settings. This could allow an attacker to perform unauthorized actions or steal session information from other users of the management console.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in GFI Archiver versions prior to 15.13. The flaw is located in the /Archiver/CategorizationPolicyWizard.aspx component, specifically within the SaveAllConfigSettings() function, which fails to perform adequate output encoding on the 'rule name' and 'email criteria' parameters. An authenticated attacker with access to classification rules can inject malicious payloads that are subsequently executed in the context of any user (typically an administrator) who views the Classification Rules page. This vulnerability is tracked as CVE-2026-48530 and is resolved in version 15.13.

Affected products

  • GFI Software Archiver before 15.13

Timeline

  • 2026-07-23: advisory
  • 2026-07-23: disclosed

References

Related threats