CVE-2026-23752 MEDIUM

CVE-2026-23752: GFI HelpDesk < 4.99.9 Stored XSS via companyname Parameter

Vendor Gfi Software
Product HelpDesk
Weakness CWE-79 · XSS
Published April 20, 2026
Last update April 20, 2026

CVSS base score

4.8/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the template group creation and editing functionality that allows authenticated administrators to inject arbitrary JavaScript by manipulating the companyname POST parameter without HTML sanitization. Attackers can inject malicious scripts through the companyname field that execute in the browsers of any administrator viewing the Templates > Groups page.

Key dates

02Disclosure timeline

April 20, 2026 CVE published
April 20, 2026 Record updated