Medium severity5.4NVD Advisory· Published Apr 20, 2026· Updated Apr 27, 2026
CVE-2026-23756
CVE-2026-23756
Description
GFI HelpDesk before 4.99.9 contains a stored cross-site scripting vulnerability in the Troubleshooter module where the subject POST parameter is not sanitized in Controller_Step.InsertSubmit() and EditSubmit() before being rendered by View_Step.RenderViewSteps(). An authenticated staff member can inject arbitrary JavaScript into the step subject field, and the payload executes when any user navigates to Troubleshooter > View Troubleshooter and clicks the affected step link.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
14- ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ StoriesThe Hacker News · May 14, 2026
- When IT Support Calls: Dissecting a ModeloRAT Campaign from Teams to Domain CompromiseRapid7 Blog · May 13, 2026
- Teams calls are about to get a lot harder to fakeHelp Net Security · May 6, 2026
- Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for monthsHelp Net Security · May 3, 2026
- This month in security with Tony Anscombe – April 2026 editionESET WeLiveSecurity · Apr 30, 2026
- BlackFile Group Targets Retail and Hospitality with Vishing AttacksInfosecurity Magazine · Apr 27, 2026
- Crime crew impersonates help desk, abuses Microsoft Teams to steal your dataThe Register Security · Apr 25, 2026
- Wordfence Intelligence Weekly WordPress Vulnerability Report (April 13, 2026 to April 19, 2026)Wordfence Blog · Apr 23, 2026
- Cyber-Attacks Surge 63% Annually in Education SectorInfosecurity Magazine · Apr 23, 2026
- Wordfence Intelligence Weekly WordPress Vulnerability Report (April 6, 2026 to April 12, 2026)Wordfence Blog · Apr 16, 2026
- As breakout time accelerates, prevention-first cybersecurity takes center stageESET WeLiveSecurity · Apr 7, 2026
- Wordfence Intelligence Weekly WordPress Vulnerability Report (March 23, 2026 to March 29, 2026)Wordfence Blog · Apr 2, 2026
- How SMBs use threat research and MDR to build a defensive edgeESET WeLiveSecurity · Mar 5, 2026
- Faking it on the phone: How to tell if a voice call is AI or notESET WeLiveSecurity · Feb 23, 2026