CVE-2026-23753
- EPSS 0.04%
- Veröffentlicht 20.04.2026 17:33:59
- Zuletzt bearbeitet 27.04.2026 15:07:29
GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the language management functionality where the charset POST parameter is passed directly to SWIFT_Language::Create() without HTML sanitization and subsequently render...
CVE-2026-23752
- EPSS 0.04%
- Veröffentlicht 20.04.2026 17:33:23
- Zuletzt bearbeitet 27.04.2026 15:07:49
GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the template group creation and editing functionality that allows authenticated administrators to inject arbitrary JavaScript by manipulating the companyname POST para...
CVE-2026-23756
- EPSS 0.03%
- Veröffentlicht 20.04.2026 17:30:51
- Zuletzt bearbeitet 27.04.2026 15:02:15
GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the subject POST parameter is not sanitized in Controller_Step.InsertSubmit() and EditSubmit() before being rendered by View_Step.Rende...
CVE-2026-23758
- EPSS 0.03%
- Veröffentlicht 20.04.2026 17:30:06
- Zuletzt bearbeitet 27.04.2026 14:58:02
GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the ticket subject field that allows authenticated staff members to inject malicious JavaScript by manipulating the editsubject POST parameter. Attackers can inject XS...
CVE-2026-23757
- EPSS 0.03%
- Veröffentlicht 20.04.2026 17:27:56
- Zuletzt bearbeitet 27.04.2026 14:59:58
GFI HelpDesk before 4.99.10 contains a stored cross-site scripting vulnerability in the Reports module where the title parameter is passed directly to SWIFT_Report::Create() without HTML sanitization. Attackers can inject arbitrary JavaScript into th...