GFI HelpDesk versions prior to 4.99.9 contain a stored cross-site scripting vulnerability in the language management feature where the charset parameter fails to properly sanitize user input before storing and displaying it. An authenticated administrator can inject malicious JavaScript through the charset field when creating or editing languages, with the payload executing in the browsers of other administrators accessing the Languages page. The vulnerability affects network-accessible GFI HelpDesk installations and requires administrator-level privileges to exploit. The vulnerability carries a CVSS score of 4.8 (Medium severity) with a network attack vector and low attack complexity. While the impact is limited to low-level confidentiality and integrity compromises with no availability impact, the requirement for high-level administrative privileges reduces overall risk. Exploitation requires user interaction, as the malicious payload only executes when other administrators view the Languages page. There is currently no evidence of active exploitation, with the vulnerability absent from CISA's Known Exploited Vulnerabilities catalog. The EPSS score of 0.00027 indicates minimal likelihood of exploitation in the wild relative to other CVEs. The vulnerability remains on an inactive hot list status with no publicly available exploit code or significant community attention, suggesting limited current threat activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.99.9CPE matchmatch criteria | cpe:2.3:a:gfi:helpdesk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.