GFI HelpDesk versions prior to 4.99.10 contain a stored cross-site scripting (XSS) vulnerability in the Reports module where user-supplied input in the report title parameter is not properly sanitized before being processed by the SWIFT_Report::Create() function. An authenticated attacker can inject malicious JavaScript code into report titles, and this payload will execute in the browsers of staff members when they view or interact with the affected report in the Manage Reports interface. The vulnerability has a CVSS score of 5.4 (Medium) and requires network access with low complexity, but necessitates user interaction and valid credentials to exploit. The attack vector is network-based, and successful exploitation could result in limited confidentiality and integrity impacts through session hijacking, credential theft, or administrative actions performed in the context of the victim's browser. There is currently no evidence of active exploitation in the wild, no public exploit code availability, and minimal community attention as reflected by the low EPSS score of 0.00029. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog and remains inactive on threat intelligence hotlists. Organizations running affected versions should apply patches at their standard maintenance cadence, prioritizing systems with high user interaction in the Reports module.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.99.10CPE matchmatch criteria | cpe:2.3:a:gfi:helpdesk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.