GestSup 3.2.62 之前的版本在 IMAP 登录连接器中未能正确对 HTML 邮件正文进行净化处理,使得未认证的攻击者能够在工单描述和回复中存储任意 JavaScript 代码。攻击者可以向被监控的邮箱发送包含 script 标签和事件处理程序的邮件,这些脚本会在技术人员浏览器中执行,从而导致工单数据泄露和未经授权的操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102373 | 6.5 MEDIUM | GestSup before 3.2.62 Private Ticket Comment Disclosure via threadedit Parameter |
| CVE-2026-102374 | 6.1 MEDIUM | GestSup before 3.2.62 Stored XSS via Double-Decoded Email Subject in OAuth IMAP Connector |
No comments yet