{"id":"CVE-2026-102373","title":"GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php","summary":"GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' ti…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-639"],"vendor":"GestSup","product":"GestSup","affected":["GestSup < 3.2.62"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T01:16:44.757","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102373","references":[{"url":"https://gestsup.fr/index.php?page=changelog","label":"disclosure@vulncheck.com"},{"url":"https://gestsup.fr/index.php?page=download","label":"disclosure@vulncheck.com"},{"url":"https://gestsup.fr/index.php?page=download&channel=stable&version=3.2.62&type=patch","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/gestsup-before-3.2.62-private-ticket-comment-disclosure-via-threadedit-parameter","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-29T01:24:51.145Z","slug":"CVE-2026-102373","body":"## Overview\n\nGestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}