CVE-2026-102373
7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GestSup | GestSup | 0 < 3.2.62 | affected |
Weaknesses
- CWE-639: Authorization Bypass Through User-Controlled Key
References
- https://gestsup.fr/index.php?page=changelog
- https://gestsup.fr/index.php?page=download
- https://gestsup.fr/index.php?page=download&channel=stable&version=3.2.62&type=patch
- https://www.vulncheck.com/advisories/gestsup-before-3.2.62-private-ticket-comment-disclosure-via-threadedit-parameter
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.