A vulnerability marked as problematic has been reported in GFI Archiver up to 15.12. This impacts the function
ImportSettingsWizard.SaveAllConfigSettings of the file /Archiver/ImportSettingsWizard.ashx of the component Import Settings. Performing a manipulation of the argument folders results in cross site scripting.
This vulnerability was named CVE-2026-48538. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.