CVE-2026-102373
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Sep 29, 2026
Vendor
unknown
Description
GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.