Loading market data...
← Back to CVE feed

CVE-2026-102372

MEDIUM CVSS 6.1 View on NVD ↗

Description

GestSup versions before 3.2.62 fail to properly sanitize HTML email bodies in the IMAP LOGIN connector, allowing unauthenticated attackers to store arbitrary JavaScript in ticket descriptions and replies. Attackers can send emails to the monitored mailbox containing script tags and event handlers that execute in technician browsers, enabling ticket data theft and unauthorized actions.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Published: Sep 29, 2026 01:16 UTC Modified: Sep 29, 2026 18:17 UTC