← back
CVE-2026-102373highCWE-639

GestSup before 3.2.62 Private Ticket Comment Disclosure via threadedit Parameter

41Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 7.1epss 0.2%
exploitation probability
0.2%top 86% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
GestSup · GestSup
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.