A vulnerability identified as problematic has been detected in GFI Archiver up to 15.12. The impacted element is the function GeneralSettingsWizard.SaveAllConfigSettings of the file /Archiver/GeneralSettingsWizard.aspx of the component SMTP Configuration. This manipulation of the argument SMTP server address causes cross site scripting.

This vulnerability is handled as CVE-2026-48536. The attack can be initiated remotely. There is not any exploit available.

You should upgrade the affected component.