CVE-2026-102373
⚪ Do wiadomości
Brak walidacji własności biletów w GestSup pozwala atakującym na odczyt prywatnych komentarzy.
CVSS
6.5
EPSS
0.2%
Exploit
none
Vendor
Opis źródłowy (NVD)
GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2026-09-29 01:16:44 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-01 16:17:34 UTC |
Referencje
- https://blog.spiizn.xyz/articles/remote-code-execution-turning-a-ticket-into-a-new-issue/ ([email protected])
- https://gestsup.fr/index.php?page=changelog ([email protected])
- https://gestsup.fr/index.php?page=download ([email protected])
- https://gestsup.fr/index.php?page=download&channel=stable&version=3.2.62&type=patch ([email protected])
- https://www.vulncheck.com/advisories/gestsup-before-3.2.62-private-ticket-comment-disclosure-via-threadedit-parameter ([email protected])