Medium severity6.5NVD Advisory· Published Sep 29, 2026
CVE-2026-102373
CVE-2026-102373
Description
GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.