Junglewise Threat Intelligence

CVE-2026-48535: GFI Archiver stored XSS in Call Home proxy configuration

CVE-2026-48535 · Severity: medium · CVSS 5.4 · Published 2026-07-23

Technologies: GFI Software Archiver. Vendors: GFI Software.

Executive brief

GFI Archiver, a solution used for archiving corporate emails and files, contains a security flaw in its configuration settings. An authorized user can inject malicious code into the system's proxy server settings, which will then run in the browsers of other administrators who view those settings. This could allow an attacker to perform unauthorized actions or steal sensitive session information from other users.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in GFI Archiver versions prior to 15.13. The flaw is located in the /Archiver/CallHomeSettingsWizard.aspx component, specifically within the proxy server address parameter. The SaveAllConfigSettings() function fails to perform proper output encoding before storing the input. An authenticated attacker can exploit this by submitting a malicious payload that is subsequently executed in the context of any user (typically an administrator) who visits the General Settings Additional Settings page. This vulnerability is tracked as CVE-2026-48535 and is resolved in version 15.13.

Affected products

  • GFI Software Archiver before 15.13

Timeline

  • 2026-07-23: disclosed
  • 2026-07-23: advisory

References

Related threats