Impact
GestSup versions before 3.2.62 contain a stored XSS flaw where the IMAP OAuth connector double‑decodes MIME‑encoded email subjects after escaping them for HTML. An attacker can send a specially crafted email containing nested MIME‑encoded‑words that inject JavaScript. When a technician opens the ticket that displays the subject, the injected script runs in the technician’s browser and can steal session cookies, deface the interface, or further exfiltrate data. The vulnerability allows an attacker with no authentication to affect any technician who views affected tickets.
Affected Systems
The affected vendor is GestSup and the affected product is GestSup, versions prior to 3.2.62. Versions 3.2.62 and later incorporate the fix that removes the double‑decoding logic. All installations that have not yet applied the 3.2.62 patch are exposed.
Risk and Exploitability
The CVSS score is 5.3, classifying it as medium severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no public exploitation reports yet. The likely attack path is simple: an unauthenticated attacker composes a malicious email and sends it to a mailbox monitored by the IMAP OAuth connector; the email’s subject line is parsed and rendered in the interface, executing JavaScript in the victim’s browser session.
OpenCVE Enrichment