Description
GestSup versions before 3.2.62 contain a stored cross-site scripting vulnerability in the IMAP OAuth connector that double-decodes MIME-encoded email subjects after HTML escaping. Unauthenticated attackers can send crafted emails to monitored mailboxes with nested MIME encoded-words to inject JavaScript that executes in technician sessions when viewing tickets.
Published: 2026-09-29
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Stored cross-site scripting in technician sessions
Action: Apply Patch
AI Analysis

Impact

GestSup versions before 3.2.62 contain a stored XSS flaw where the IMAP OAuth connector double‑decodes MIME‑encoded email subjects after escaping them for HTML. An attacker can send a specially crafted email containing nested MIME‑encoded‑words that inject JavaScript. When a technician opens the ticket that displays the subject, the injected script runs in the technician’s browser and can steal session cookies, deface the interface, or further exfiltrate data. The vulnerability allows an attacker with no authentication to affect any technician who views affected tickets.

Affected Systems

The affected vendor is GestSup and the affected product is GestSup, versions prior to 3.2.62. Versions 3.2.62 and later incorporate the fix that removes the double‑decoding logic. All installations that have not yet applied the 3.2.62 patch are exposed.

Risk and Exploitability

The CVSS score is 5.3, classifying it as medium severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no public exploitation reports yet. The likely attack path is simple: an unauthenticated attacker composes a malicious email and sends it to a mailbox monitored by the IMAP OAuth connector; the email’s subject line is parsed and rendered in the interface, executing JavaScript in the victim’s browser session.

Generated by OpenCVE AI on September 29, 2026 at 02:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade GestSup to version 3.2.62 or later to remove the double‑decoding logic.
  • If an upgrade is not immediately possible, disable the IMAP OAuth connector or block incoming emails to prevent malicious subject parsing.
  • As a temporary workaround, configure the mail gateway or web interface to strip or validate MIME‑encoded words before storing or displaying email subjects.

Generated by OpenCVE AI on September 29, 2026 at 02:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description GestSup versions before 3.2.62 contain a stored cross-site scripting vulnerability in the IMAP OAuth connector that double-decodes MIME-encoded email subjects after HTML escaping. Unauthenticated attackers can send crafted emails to monitored mailboxes with nested MIME encoded-words to inject JavaScript that executes in technician sessions when viewing tickets.
Title GestSup before 3.2.62 Stored XSS via Double-Decoded Email Subject in OAuth IMAP Connector
First Time appeared Gestsup
Gestsup gestsup
Weaknesses CWE-79
CPEs cpe:2.3:a:gestsup:gestsup:*:*:*:*:*:*:*:*
Vendors & Products Gestsup
Gestsup gestsup
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-29T00:33:24.255Z

Reserved: 2026-09-28T23:57:27.220Z

Link: CVE-2026-102374

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T01:16:44.900

Modified: 2026-09-29T01:16:44.900

Link: CVE-2026-102374

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T02:30:10Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')