CVE-2026-102373 - GestSup before 3.2.62 Private Ticket Comment Disclosure via threadedit Parameter
CVE ID :CVE-2026-102373
Published : Sept. 29, 2026, 12:33 a.m. | 39 minutes ago
Description :GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 29, 2026, 12:33 a.m. | 39 minutes ago
Description :GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...