What is CVE-2026-48536?
GFI Archiver before version 15.13 contains a stored cross-site scripting (XSS) vulnerability in the SMTP configuration settings. This allows an authenticated attacker to inject arbitrary web script or HTML via the SMTP server address parameter, potentially affecting other users of the application. Users must upgrade to version 15.13 or later to mitigate this issue.
Azərbaycanca: GFI Archiver-in 15.13 versiyasından əvvəlki versiyalarında SMTP konfiqurasiya parametrində saxlanılan XSS (stored cross-site scripting) zəifliyi aşkarlanıb. Bu, autentifikasiya olunmuş hücumçuya SMTP server ünvanı vasitəsilə ixtiyari veb skript və ya HTML kodu daxil etməyə imkan verir. GFI Archiver istifadəçiləri dərhal 15.13 və ya daha yuxarı versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: GFI
FAQ1
In which component of GFI Archiver was the stored XSS vulnerability discovered?
This vulnerability was discovered in the SMTP configuration settings of GFI Archiver, specifically via the SMTP server address parameter. It could allow an authenticated attacker to inject arbitrary web script or HTML.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.