GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. (CVE-2026-102373)
GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.
AI Analysis
Technical Summary
GestSup before version 3.2.62 fails to validate ticket ownership during comment retrieval using the threadedit parameter in thread.php. Authenticated users can exploit this by enumerating sequential comment IDs to read private comments from other users' tickets without proper authorization checks. This is classified under CWE-639 (Authorization Bypass Through User-Controlled Key). The vulnerability impacts confidentiality but does not affect integrity or availability.
Potential Impact
An authenticated attacker can read private comments from tickets they do not own by exploiting the lack of ownership validation. This leads to unauthorized disclosure of sensitive information contained in private comments. There is no indication of impact on data integrity or system availability.
Mitigation Recommendations
A fix is available in GestSup version 3.2.62. Users should upgrade to version 3.2.62 or later to remediate this vulnerability. No additional mitigation steps are indicated.
GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. (CVE-2026-102373)
Description
GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.
CVSS v3.1
Score 6.5medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
GestSup before version 3.2.62 fails to validate ticket ownership during comment retrieval using the threadedit parameter in thread.php. Authenticated users can exploit this by enumerating sequential comment IDs to read private comments from other users' tickets without proper authorization checks. This is classified under CWE-639 (Authorization Bypass Through User-Controlled Key). The vulnerability impacts confidentiality but does not affect integrity or availability.
Potential Impact
An authenticated attacker can read private comments from tickets they do not own by exploiting the lack of ownership validation. This leads to unauthorized disclosure of sensitive information contained in private comments. There is no indication of impact on data integrity or system availability.
Mitigation Recommendations
A fix is available in GestSup version 3.2.62. Users should upgrade to version 3.2.62 or later to remediate this vulnerability. No additional mitigation steps are indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-wcm4-67q4-6r6m
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-102373"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6abb4178f7a7c54106cc2e32
Added to database: 09/29/2026, 04:41:28 UTC
Last enriched: 09/29/2026, 04:43:15 UTC
Last updated: 09/29/2026, 18:11:16 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.