What is CVE-2026-48537?
GFI Archiver before version 15.13 contains a stored cross-site scripting (XSS) vulnerability in the File Archive Assistant configuration, allowing authenticated attackers to inject arbitrary web script via the 'excluded extensions' parameter. Users should immediately upgrade to version 15.13 or later to mitigate this issue.
Azərbaycanca: GFI Archiver-in 15.13-dən əvvəlki versiyalarında aşkarlanan CVE-2026-48537 saxlanılan XSS zəifliyi autentifikasiya olunmuş hücumçulara File Archive Assistant konfiqurasiyasındakı `excluded extensions` parametri vasitəsilə ixtiyari veb skript yeritməyə imkan verir. GFI Archiver istifadəçiləri təcili olaraq 15.13 və ya daha yuxarı versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: GFI
FAQ2
In which component of GFI Archiver does the CVE-2026-48537 vulnerability exist?
The vulnerability is a stored XSS in the `excluded extensions` parameter within the File Archive Assistant configuration.
What measure should be taken to mitigate the CVE-2026-48537 vulnerability?
Users should immediately upgrade GFI Archiver to version 15.13 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.