Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gfi Software
Gfi Software gfi Archiver |
|
| Vendors & Products |
Gfi Software
Gfi Software gfi Archiver |
|
| Metrics |
ssvc
|
Thu, 23 Jul 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the server URL parameter to /Archiver/ImapServerWizard.aspx. The injected payload is stored by ImapServerWizard.SaveAllConfigSettings() without output encoding and is executed in the browsers of users who subsequently view the IMAP Server configuration page. | |
| Title | GFI Archiver < 15.13 Stored XSS via ImapServerWizard.aspx | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-23T15:44:04.069Z
Reserved: 2026-05-21T18:34:46.417Z
Link: CVE-2026-48534
Updated: 2026-07-23T15:43:58.603Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-27T07:00:04Z