VYPR
Medium severity6.5NVD Advisory· Published Sep 29, 2026

CVE-2026-102373

CVE-2026-102373

Description

GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.