Retour à la veille

CVE-2026-102373

Publié : 29 septembre 2026
Modifié : 29 septembre 2026
Lien officiel NVD
Score CVSS
6.5
MEDIUM

Description détaillée

GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Références et Patchs