5.1
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Description
GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the subject POST parameter is not sanitized in Controller_Step.InsertSubmit() and EditSubmit() before being rendered by View_Step.RenderViewSteps(). An authenticated staff member can inject arbitrary JavaScript into the step subject field, and the payload executes when any user navigates to Troubleshooter > View Troubleshooter and clicks the affected step link.
Basic Information
ID
CVE-2026-23756
Source
VulnCheck
Published
Apr 20, 2026 at 17:30
Modified
Apr 20, 2026 at 18:08
Affected Product
Vendor
GFI Software
Product
HelpDesk
Affected Versions
GFI Software HelpDesk 0