Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100389— GestSup before 3.2.61 Remote Code Execution via IMAP Attachment

Quick assessment

Affected
GestSup GestSup
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GestSup 3.2.61 之前的版本存在一个远程代码执行漏洞,该漏洞位于基础 IMAP 连接器处理附件的逻辑中,由于未能正确跳过被阻止的文件扩展名,攻击者可以在未认证的情况下,向被监控的邮箱发送包含 PHP 附件的邮件。这些附件会被写入到可通过 Web 访问的 upload/ticket 目录,并在被访问时执行。

CVSS 8.1 · High EPSS 0.57% · P45
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100389

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
GestSup before 3.2.61 Remote Code Execution via IMAP Attachment
Source: CVE Program / CVE List V5
Vulnerability Description
GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
危险类型文件的不加限制上传
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
GestSup GestSup 0 ~ 3.2.61 -

II. Public POCs for CVE-2026-100389

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100389

请登录查看更多情报信息。

Vendor Pages for CVE-2026-100389 (1)

Other References for CVE-2026-100389 (1)

Other References for CVE-2026-100389 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-100389

No comments yet


Leave a comment