CVE-2026-102372
Received Received - Intake

Stored XSS in GestSup via Malicious HTML Emails

Vulnerability report for CVE-2026-102372, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

GestSup versions before 3.2.62 fail to properly sanitize HTML email bodies in the IMAP LOGIN connector, allowing unauthenticated attackers to store arbitrary JavaScript in ticket descriptions and replies. Attackers can send emails to the monitored mailbox containing script tags and event handlers that execute in technician browsers, enabling ticket data theft and unauthorized actions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gestsup gestsup to 3.2.62 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

GestSup versions before 3.2.62 fail to sanitize HTML email bodies in the IMAP LOGIN connector. This allows unauthenticated attackers to inject malicious JavaScript into ticket descriptions and replies via email. When technicians view these tickets, the embedded scripts execute in their browsers, enabling potential data theft or unauthorized actions.

Detection Guidance

Check GestSup versions before 3.2.62 by inspecting the software version in the admin panel or via database queries. Monitor email logs for HTML emails with script tags or event handlers in ticket descriptions. Inspect browser console logs when technicians view tickets for unexpected JavaScript execution.

Impact Analysis

This vulnerability allows attackers to steal ticket data or perform unauthorized actions when technicians view compromised tickets. It could lead to data breaches, unauthorized access to sensitive information, or manipulation of support tickets.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data stored in tickets, such as personal or health information, which may violate GDPR and HIPAA compliance requirements for data protection and confidentiality.

Mitigation Strategies

Upgrade to GestSup version 3.2.62 or later immediately. Disable the IMAP LOGIN connector if not required. Implement input validation for email bodies and sanitize HTML content before storage. Monitor ticket systems for unauthorized changes or suspicious scripts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102372. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart