← volver
CVE-2026-100389criticalCWE-434

GestSup before 3.2.61 Remote Code Execution via IMAP Attachment

28Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 9.2epss 0.6%
probabilidad de explotación
0.6%top 55% de las CVE
explotación observada
noninguna fuente lo reporta
GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
GestSup · GestSup