CVE-2026-102373 PUBLISHED

GestSup before 3.2.62 Private Ticket Comment Disclosure via threadedit Parameter

Assigner: VulnCheck
Reserved: 28.09.2026 Published: 29.09.2026 Updated: 29.09.2026

GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor GestSup
Product GestSup
Versions Default: unaffected
  • affected from 0 to 3.2.62 (excl.)

Credits

  • SpiizN finder

References

Problem Types

  • Authorization Bypass Through User-Controlled Key CWE