OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-102373 (CVSS 7.1)

NVD · officialPublished Sep 29, 2026Risk 23/100

GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.

CVSS
7.1
AV:NetworkAC:LowPR:LowUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source