Description
GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 25 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed. | |
| Title | GestSup before 3.2.61 Remote Code Execution via IMAP Attachment | |
| First Time appeared |
Gestsup
Gestsup gestsup |
|
| Weaknesses | CWE-434 | |
| CPEs | cpe:2.3:a:gestsup:gestsup:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gestsup
Gestsup gestsup |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-25T20:13:07.623Z
Reserved: 2026-09-25T19:47:52.073Z
Link: CVE-2026-100389
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-434
Unrestricted Upload of File with Dangerous Type