CVE-2026-102373: Gestsup

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.

Affected products

  • Gestsup Gestsup: before 3.2.62 (fixed in 3.2.62)

Published 2026-09-29. Last modified 2026-10-01.