Executive brief
GFI Archiver, a solution used for archiving business emails and files, contains a security flaw in its File Archive Assistant configuration. An authenticated user can inject malicious scripts into the system's settings. If an administrator or another user later views these settings, the script could execute in their browser, potentially allowing the attacker to perform unauthorized actions or access sensitive session information.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in GFI Archiver versions prior to 15.13. The flaw is located in the File Archive Assistant configuration wizard (/Archiver/FileArchiveAssistantWizard.aspx) within the 'excluded extensions' parameter. The application's btnSave_Click() function fails to perform adequate output encoding before storing the input. An authenticated attacker can exploit this by submitting a malicious payload that executes in the context of any user who subsequently visits the File Archive Assistant settings page. This can lead to session hijacking or unauthorized administrative actions. The issue is resolved in version 15.13.
Affected products
- GFI Software Archiver before 15.13
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory