GFI HelpDesk versions prior to 4.99.9 contain a stored cross-site scripting vulnerability in the template group creation and editing functionality. The vulnerability exists in the companyname POST parameter, which lacks proper HTML sanitization, allowing authenticated administrators to inject arbitrary JavaScript code. When other administrators view the Templates > Groups page, the malicious scripts execute in their browsers, potentially compromising administrative functions and sensitive data. The vulnerability carries a CVSS v3.1 score of 4.8 (Medium severity) with a network-based attack vector, low attack complexity, and high privilege requirements. While the attack requires administrator-level access and user interaction to view the affected page, it can affect the confidentiality and integrity of administrator sessions across the network. The EPSS score of 0.00027 indicates minimal exploitation likelihood compared to other vulnerabilities in the database. The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and remains inactive on threat intelligence hot lists. There is no evidence of active exploitation or publicly available exploit code at this time. Organizations using affected GFI HelpDesk versions should prioritize updating to version 4.99.9 or later, though the low exploitation risk suggests this is a moderate-priority patch deployment.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.99.9CPE matchmatch criteria | cpe:2.3:a:gfi:helpdesk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.