Loading market data...
← Back to CVE feed

CVE-2026-102373

MEDIUM CVSS 6.5 View on NVD ↗

Description

GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Published: Sep 29, 2026 01:16 UTC Modified: Sep 29, 2026 01:16 UTC