---
id: CVE-2026-102373
title: >-
  GestSup versions before 3.2.62 fail to validate ticket ownership when loading
  comments via the threadedit parameter in thread.php
summary: >-
  GestSup versions before 3.2.62 fail to validate ticket ownership when loading
  comments via the threadedit parameter in thread.php. Authenticated attackers
  can enumerate sequential comment IDs to read private comments from other
  users' ti…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-639
vendor: GestSup
product: GestSup
affected:
  - GestSup < 3.2.62
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T01:16:44.757'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102373'
references:
  - url: 'https://gestsup.fr/index.php?page=changelog'
    label: disclosure@vulncheck.com
  - url: 'https://gestsup.fr/index.php?page=download'
    label: disclosure@vulncheck.com
  - url: >-
      https://gestsup.fr/index.php?page=download&channel=stable&version=3.2.62&type=patch
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/gestsup-before-3.2.62-private-ticket-comment-disclosure-via-threadedit-parameter
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T01:24:51.145Z'
---

## Overview

GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
