Impact
GestSup versions prior to 3.2.62 contain a flaw that allows authenticated users to obtain private ticket comments from other users. When a signed‑in user accesses thread.php with the threadedit parameter, the application does not verify that the ticket belongs to the requester, enabling enumeration of comment identifiers. The weakness is a classic authorization bypass (CWE‑639) and can lead to the compromise of confidential data stored in private comments.
Affected Systems
GestSup 3.2.61 and earlier. The vulnerability affects the GestSup ticketing application as distributed by GestSup. Users running any pre‑3.2.62 release are susceptible, regardless of deployment size or environment.
Risk and Exploitability
The CVSS score of 7.1 indicates a High severity, while the EPSS score is unavailable, so the current exploitation probability is unknown but the flaw is actively exploitable by any authenticated user. The issue is not listed in CISA KEV, suggesting it is not a currently known exploited vulnerability, but its severity remains significant. Attackers would simply need valid credentials and then submit sequential comment IDs via the threadedit parameter to recover private comments from other tickets.
OpenCVE Enrichment