GestSup before 3.2.62 Private Ticket Comment Disclosure via threadedit Parameter
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 7.1epss 0.2%
exploitation probability
0.2%top 86% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
GestSup · GestSuppublic PoCs found — 1
cve_referenceblog.spiizn.xyz/articles/remote-code-execution-turning-a-ticket-into-a-new-issue/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://blog.spiizn.xyz/articles/remote-code-execution-turning-a-ticket-into-a-new-issue/https://gestsup.fr/index.php?page=changeloghttps://gestsup.fr/index.php?page=downloadhttps://gestsup.fr/index.php?page=download&channel=stable&version=3.2.62&type=patchhttps://www.vulncheck.com/advisories/gestsup-before-3.2.62-private-ticket-comment-disclosure-via-threadedit-parameter