Sceawere

Vulnerability Detail

CVE-2026-102372UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GestSup Stored Cross-Site Scripting

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
6h ago
Vendor
GestSup
Product
GestSup
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

GestSup versions before 3.2.62 fail to properly sanitize HTML email bodies in the IMAP LOGIN connector, allowing unauthenticated attackers to store arbitrary JavaScript in ticket descriptions and replies. Attackers can send emails to the monitored mailbox containing script tags and event handlers that execute in technician browsers, enabling ticket data theft and unauthorized actions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-09-29T01:16:44.593Z",
  "pubdate": "2026-09-29T01:16:44.593Z",
  "executiveSummary": "GestSup versions prior to 3.2.62 are vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability within the IMAP LOGIN connector.\nThe vulnerability stems from improper sanitization of HTML content within incoming email bodies processed by the application.\nUnauthenticated attackers can leverage this flaw by sending specially crafted emails to a monitored mailbox, which the system then automatically ingests and renders in the technician interface.\nThe successful exploitation of this vulnerability results in the execution of arbitrary JavaScript in the context of a technician's browser session.\nImpact includes the potential for unauthorized administrative actions, the theft of sensitive session data, and the compromise of ticket information.\nBecause the vector is the email processing subsystem, the attack does not require direct interaction with the GestSup web interface by the attacker, making it a critical threat to the integrity and confidentiality of the helpdesk platform.",
  "technicalDetails": "The root cause of this vulnerability is the failure of the GestSup IMAP LOGIN connector to perform rigorous input validation and output encoding on the HTML bodies of incoming emails before rendering them within the application's ticket management interface.\nWhen the IMAP connector polls a mailbox, it retrieves the raw MIME content of incoming messages. If the body contains HTML, the application parses and stores the content directly into the database as part of the ticket description or reply stream.\nBecause there is no server-side sanitization mechanism to strip malicious elements—such as <script> tags, <iframe> elements, or inline event handlers like 'onerror' or 'onload'—the malicious payload is persisted in the database.\nThe attack flow proceeds as follows: First, an unauthenticated attacker composes an email containing a malicious JavaScript payload embedded within an HTML tag. Second, the attacker sends this email to the mailbox monitored by GestSup. Third, the IMAP connector fetches the message, extracts the malicious HTML, and inserts it into the database.\nFinally, when a technician accesses the ticket via the web interface, the application retrieves the stored data and renders the tainted HTML directly into the DOM of the technician's browser session. At this point, the JavaScript payload executes with the privileges of the authenticated technician.\nThe execution of arbitrary JavaScript allows the attacker to perform several post-exploitation actions, including stealing session cookies via 'document.cookie', performing unauthorized API requests on behalf of the technician, or exfiltrating private ticket data to a remote command-and-control server.\nThis vulnerability is particularly dangerous because it bypasses perimeter security, as the attack is initiated through the standard email protocol (IMAP/SMTP) rather than a direct request to the web application. The affected component is the internal IMAP processing logic present in all versions before 3.2.62. No authentication is required to initiate the delivery of the malicious email, effectively allowing an attacker to achieve code execution in a privileged user's environment by merely knowing the destination support address."
}
CVE-2026-102372: GestSup Stored Cross-Site Scripting (MEDIUM Severity, CVSS: 6.1) | Sceawere