Description
GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.
Published: 2026-09-29
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Patch Now
AI Analysis

Impact

GestSup versions prior to 3.2.62 contain a flaw that allows authenticated users to obtain private ticket comments from other users. When a signed‑in user accesses thread.php with the threadedit parameter, the application does not verify that the ticket belongs to the requester, enabling enumeration of comment identifiers. The weakness is a classic authorization bypass (CWE‑639) and can lead to the compromise of confidential data stored in private comments.

Affected Systems

GestSup 3.2.61 and earlier. The vulnerability affects the GestSup ticketing application as distributed by GestSup. Users running any pre‑3.2.62 release are susceptible, regardless of deployment size or environment.

Risk and Exploitability

The CVSS score of 7.1 indicates a High severity, while the EPSS score is unavailable, so the current exploitation probability is unknown but the flaw is actively exploitable by any authenticated user. The issue is not listed in CISA KEV, suggesting it is not a currently known exploited vulnerability, but its severity remains significant. Attackers would simply need valid credentials and then submit sequential comment IDs via the threadedit parameter to recover private comments from other tickets.

Generated by OpenCVE AI on September 29, 2026 at 02:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade GestSup to version 3.2.62 or later where the authorization check for ticket ownership has been implemented.
  • If an upgrade is not feasible, apply the vendor‑supplied patch from the Stable channel that addresses the threadedit parameter validation.
  • Review custom extensions or modules that interact with ticket comments to ensure they enforce ownership checks before exposing comment data.

Generated by OpenCVE AI on September 29, 2026 at 02:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.
Title GestSup before 3.2.62 Private Ticket Comment Disclosure via threadedit Parameter
First Time appeared Gestsup
Gestsup gestsup
Weaknesses CWE-639
CPEs cpe:2.3:a:gestsup:gestsup:*:*:*:*:*:*:*:*
Vendors & Products Gestsup
Gestsup gestsup
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-29T00:33:23.523Z

Reserved: 2026-09-28T23:57:26.858Z

Link: CVE-2026-102373

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T01:16:44.757

Modified: 2026-09-29T01:16:44.757

Link: CVE-2026-102373

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T02:30:10Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key