Sceawere

Vulnerability Detail

CVE-2026-102374UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GestSup IMAP Stored XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.1
Creation Date
6h ago
Vendor
GestSup
Product
GestSup
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

GestSup versions before 3.2.62 contain a stored cross-site scripting vulnerability in the IMAP OAuth connector that double-decodes MIME-encoded email subjects after HTML escaping. Unauthenticated attackers can send crafted emails to monitored mailboxes with nested MIME encoded-words to inject JavaScript that executes in technician sessions when viewing tickets.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.1",
  "pubDate": "2026-09-29T01:16:44.900Z",
  "pubdate": "2026-09-29T01:16:44.900Z",
  "executiveSummary": "GestSup versions prior to 3.2.62 are susceptible to a stored Cross-Site Scripting (XSS) vulnerability within the IMAP OAuth connector.\nThe flaw stems from improper handling of MIME-encoded email subjects, which undergo double-decoding after initial HTML escaping measures are applied.\nThis vulnerability allows unauthenticated remote attackers to trigger malicious script execution within the browser sessions of authenticated technicians.\nBy sending a specially crafted email to a monitored mailbox, an attacker can achieve persistent injection, potentially leading to unauthorized actions, session hijacking, or sensitive information theft when a technician views the ticket created from the malicious email.\nThe risk is significant due to the automated nature of ticket processing systems, which serve as an entry point for malicious payloads without requiring interaction from the target beyond standard ticket management procedures.",
  "technicalDetails": "The vulnerability is located within the IMAP OAuth connector component responsible for parsing incoming mail to generate support tickets. The application fails to maintain a secure sequence of data sanitization, specifically regarding the processing of MIME-encoded-words in email subject lines.\nThe root cause is a double-decoding logic flaw. When the application receives an email, it first applies HTML escaping to sanitize input. However, subsequent processing routines perform an additional layer of MIME-decoding on the subject string. This operation effectively reverses or bypasses the previous security encoding, re-introducing dangerous characters such as script tags or event handlers that were previously neutralized.\nThe exploitation flow is as follows: An unauthenticated attacker crafts an email where the subject line contains nested or specifically formatted MIME encoded-words (e.g., =?UTF-8?B?...?=). By carefully embedding JavaScript syntax within these encoded segments, the attacker bypasses static filters. When the IMAP connector polls the mailbox, it fetches the malicious subject and performs the faulty decoding process, storing the resulting executable script into the application database as part of the ticket metadata.\nThe impact manifests when a technician or administrative user accesses the GestSup dashboard to view the generated ticket. The application renders the stored subject line in the technician's browser session. Because the browser interprets the decoded, malicious payload as valid HTML/JavaScript, the payload executes in the context of the technician’s active session.\nThis vulnerability does not require authentication for the attacker, as the entry point is an external email mailbox processed by the server-side connector. Successful exploitation allows for the execution of arbitrary JavaScript, which can be leveraged to exfiltrate session cookies, perform unauthorized actions on behalf of the technician, or pivot within the application's administrative interface, depending on the privileges of the affected technician session."
}
CVE-2026-102374: GestSup IMAP Stored XSS Vulnerability (MEDIUM Severity, CVSS: 6.1) | Sceawere