Executive brief
GFI Archiver, a solution used by businesses to archive and manage email and file history, is vulnerable to a security flaw in its policy configuration settings. An authorized user can inject malicious scripts into the system by naming a retention policy with a specially crafted string. If another administrator later views the list of policies, that script will run in their browser, potentially allowing the attacker to perform unauthorized actions or steal session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in GFI Archiver versions prior to 15.13. The flaw is located in the /Archiver/FAARetentionPolicyWizard.aspx component, specifically within the policy name parameter. The application's RetentionPolicyWizard.SaveAllConfigSettings() function fails to perform adequate output encoding before storing the input. An authenticated attacker with sufficient privileges to create or modify retention policies can inject a malicious payload that executes in the context of any user (typically an administrator) who views the File History Retention Policies page. This issue is resolved in version 15.13.
Affected products
- GFI Software Archiver before 15.13
Timeline
- 2026-07-23: advisory
- 2026-07-23: disclosed