GestSup before 3.2.62 Private Ticket Comment Disclosure via threadedit Parameter
41Vexday Risk Score
Sem sinal de exploração. Ela tem prova de conceito pública.
ssvc Attendcvss 7.1epss 0.2%
probabilidade de exploração
0.2%top 86% das CVEs
exploração observada
nãonenhuma fonte reporta
1 exploit(s) público(s)
GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Produtos afetados
GestSup · GestSupPoCs públicas encontradas — 1
cve_referenceblog.spiizn.xyz/articles/remote-code-execution-turning-a-ticket-into-a-new-issue/não verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Referências
https://blog.spiizn.xyz/articles/remote-code-execution-turning-a-ticket-into-a-new-issue/https://gestsup.fr/index.php?page=changeloghttps://gestsup.fr/index.php?page=downloadhttps://gestsup.fr/index.php?page=download&channel=stable&version=3.2.62&type=patchhttps://www.vulncheck.com/advisories/gestsup-before-3.2.62-private-ticket-comment-disclosure-via-threadedit-parameter