---
id: CVE-2026-102374
title: >-
  GestSup versions before 3.2.62 contain a stored cross-site scripting
  vulnerability in the IMAP OAuth connector that double-decodes MIME-encoded
  email subjects after HTML escaping
summary: >-
  GestSup versions before 3.2.62 contain a stored cross-site scripting
  vulnerability in the IMAP OAuth connector that double-decodes MIME-encoded
  email subjects after HTML escaping. Unauthenticated attackers can send crafted
  emails to moni…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: GestSup
product: GestSup
affected:
  - GestSup < 3.2.62
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T01:16:44.900'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102374'
references:
  - url: 'https://gestsup.fr/index.php?page=changelog'
    label: disclosure@vulncheck.com
  - url: 'https://gestsup.fr/index.php?page=download'
    label: disclosure@vulncheck.com
  - url: >-
      https://gestsup.fr/index.php?page=download&channel=stable&version=3.2.62&type=patch
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/gestsup-before-3.2.62-stored-xss-via-double-decoded-email-subject-in-oauth-imap-connector
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T01:24:51.146Z'
---

## Overview

GestSup versions before 3.2.62 contain a stored cross-site scripting vulnerability in the IMAP OAuth connector that double-decodes MIME-encoded email subjects after HTML escaping. Unauthenticated attackers can send crafted emails to monitored mailboxes with nested MIME encoded-words to inject JavaScript that executes in technician sessions when viewing tickets.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
