Sceawere

Vulnerability Detail

CVE-2026-102373UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GestSup Unauthorized Comment Access Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
6h ago
Vendor
GestSup
Product
GestSup
Attack Type
Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users' tickets without proper authorization checks.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-29T01:16:44.757Z",
  "pubdate": "2026-09-29T01:16:44.757Z",
  "executiveSummary": "An Insecure Direct Object Reference (IDOR) vulnerability exists in GestSup versions prior to 3.2.62, specifically within the thread.php file.\nThe vulnerability originates from a failure to validate user ownership of ticket comments retrieved via the threadedit parameter.\nAuthenticated attackers can leverage this flaw to perform unauthorized enumeration of comment IDs, leading to the exposure of sensitive communication and private data across different user tickets.\nThe impact is significant, as it facilitates unauthorized access to confidential organizational or personal information stored within the ticketing system.\nSuccessful exploitation requires the attacker to hold an authenticated account within the GestSup environment, though no elevated administrative privileges are necessary to conduct the attack.\nThe risk is categorized as high due to the ease of automation and the potential for large-scale data exfiltration of internal helpdesk discussions.",
  "technicalDetails": "The vulnerability resides in the application's server-side logic responsible for rendering ticket comment threads, specifically implemented in thread.php.\nThe root cause is a deficiency in the access control mechanism: the application accepts the 'threadedit' parameter to identify a specific comment for retrieval or editing but fails to verify if the requesting session's user ID possesses the necessary authorization to view the resource associated with that comment ID.\nUnder normal operations, when a user accesses a ticket, the system should validate the user's relationship with the ticket ID before serving comment content. However, the implementation within thread.php treats the comment identifier as a trusted pointer without performing an underlying permission check against the active session's scope.\nAttackers can exploit this via a systematic enumeration strategy. By manipulating the 'threadedit' parameter in an HTTP GET or POST request directed at thread.php, an attacker can iterate through sequential integer values representing comment IDs.\nBecause the server lacks a cross-check between the authenticated user's session and the owner of the comment associated with the provided ID, the application returns the content of private comments belonging to any ticket in the system regardless of the user's actual permissions.\nThe attack flow follows a predictable pattern: 1) The attacker authenticates to the GestSup platform. 2) The attacker intercepts or crafts a request to thread.php. 3) The attacker modifies the 'threadedit' parameter value to target arbitrary sequential integers. 4) The server processes the request, bypasses access checks, and serves the requested comment data in the response body.\nThis vulnerability is present in all versions prior to 3.2.62. It exposes the application to mass data scraping, where an attacker can script the enumeration process to pull the entire history of internal communications, incident reports, and potentially sensitive user metadata or credentials shared within tickets.\nThe vulnerability is persistent across the web interface and does not require specific environmental configurations other than a functional authenticated account, representing a severe failure in the application's authorization layer."
}
CVE-2026-102373: GestSup Unauthorized Comment Access Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere