GestSup 3.2.62 之前的版本在 IMAP OAuth 连接器中存在一个存储型跨站脚本(Stored Cross-Site Scripting, XSS)漏洞。该漏洞会在进行 HTML 转义后,对 MIME 编码的邮件主题进行双重解码。未授权的攻击者可以向被监控的邮箱发送构造的邮件,其中包含嵌套的 MIME 编码词,从而注入 JavaScript 代码。当技术人员在查看工单时,这些恶意脚本将在其会话中执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102373 | 6.5 MEDIUM | GestSup before 3.2.62 Private Ticket Comment Disclosure via threadedit Parameter |
| CVE-2026-102372 | 6.1 MEDIUM | GestSup before 3.2.62 Stored XSS via Email Body in LOGIN IMAP Connector |
No comments yet