A vulnerability labeled as problematic has been found in GFI Archiver up to 15.12. This affects the function FileArchiveAssistantWizard.btnSave_Click of the file /Archiver/FileArchiveAssistantWizard.aspx of the component File Archive Assistant. Such manipulation of the argument excluded extensions leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2026-48537. The attack can be launched remotely. No exploit exists.

The affected component should be upgraded.