在版本低于 3.2.62 的 GestSup 系统中,当通过 thread.php 的 threadedit 参数加载评论时,未能验证评论的所有权。经过身份验证的攻击者可以枚举连续的评论 ID,从而在未经适当授权检查的情况下读取其他用户工单中的私有评论。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102372 | 6.1 MEDIUM | GestSup before 3.2.62 Stored XSS via Email Body in LOGIN IMAP Connector |
| CVE-2026-102374 | 6.1 MEDIUM | GestSup before 3.2.62 Stored XSS via Double-Decoded Email Subject in OAuth IMAP Connector |
No comments yet