---
cve: "CVE-2026-102373"
severity: "HIGH"
cvss: 7.1
epss: "0.2%"
vendor: "GestSup"
kev: false
exploited: false
published: "2026-09-29 01:16:44"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-10-05T00:14:00+02:00"
---

# CVE-2026-102373

> 7.1 HIGH

## Beschreibung

GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.

## CNA-Record (Kanon, cvelistV5)

- CNA: **VulnCheck**
- State: PUBLISHED
- Stand: 2026-10-01 15:26:09
- CNA-CVSS: **7.1** (`CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N`)

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **poc**
  - Automatable: **no**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://gestsup.fr/index.php?page=changelog>
- <https://gestsup.fr/index.php?page=download>
- <https://gestsup.fr/index.php?page=download&channel=stable&version=3.2.62&type=patch>
- <https://www.vulncheck.com/advisories/gestsup-before-3.2.62-private-ticket-comment-disclosure-via-threadedit-parameter>
- <https://blog.spiizn.xyz/articles/remote-code-execution-turning-a-ticket-into-a-new-issue/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-102373) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
