{"id":"CVE-2026-102374","title":"GestSup versions before 3.2.62 contain a stored cross-site scripting vulnerability in the IMAP OAuth connector that double-decodes MIME-encoded email subjects after HTML escaping","summary":"GestSup versions before 3.2.62 contain a stored cross-site scripting vulnerability in the IMAP OAuth connector that double-decodes MIME-encoded email subjects after HTML escaping. Unauthenticated attackers can send crafted emails to moni…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"GestSup","product":"GestSup","affected":["GestSup < 3.2.62"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T01:16:44.900","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102374","references":[{"url":"https://gestsup.fr/index.php?page=changelog","label":"disclosure@vulncheck.com"},{"url":"https://gestsup.fr/index.php?page=download","label":"disclosure@vulncheck.com"},{"url":"https://gestsup.fr/index.php?page=download&channel=stable&version=3.2.62&type=patch","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/gestsup-before-3.2.62-stored-xss-via-double-decoded-email-subject-in-oauth-imap-connector","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-29T01:24:51.146Z","slug":"CVE-2026-102374","body":"## Overview\n\nGestSup versions before 3.2.62 contain a stored cross-site scripting vulnerability in the IMAP OAuth connector that double-decodes MIME-encoded email subjects after HTML escaping. Unauthenticated attackers can send crafted emails to monitored mailboxes with nested MIME encoded-words to inject JavaScript that executes in technician sessions when viewing tickets.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}