CVE-2026-102374
Received Received - Intake

Stored XSS in GestSup IMAP OAuth Connector via MIME-Encoded Email Subjects

Vulnerability report for CVE-2026-102374, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

GestSup versions before 3.2.62 contain a stored cross-site scripting vulnerability in the IMAP OAuth connector that double-decodes MIME-encoded email subjects after HTML escaping. Unauthenticated attackers can send crafted emails to monitored mailboxes with nested MIME encoded-words to inject JavaScript that executes in technician sessions when viewing tickets.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gestsup gestsup to 3.2.62 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in GestSup versions before 3.2.62. It involves double-decoding MIME-encoded email subjects after HTML escaping in the IMAP OAuth connector. Attackers can send crafted emails with nested MIME encoded-words to inject JavaScript that executes when technicians view tickets.

Detection Guidance

Detecting this vulnerability requires monitoring for crafted emails with nested MIME encoded-words in email subjects. Inspect email headers and subjects for double-encoded MIME content. Check GestSup logs for unusual JavaScript execution in technician sessions when viewing tickets.

Impact Analysis

Unauthenticated attackers could execute malicious JavaScript in technician sessions when viewing tickets containing specially crafted emails. This could lead to unauthorized actions, data theft, or session hijacking within the GestSup application.

Compliance Impact

This vulnerability could potentially violate GDPR and HIPAA compliance by enabling unauthorized script execution in technician sessions. Stored XSS attacks may lead to data breaches, unauthorized access to sensitive information, or manipulation of support tickets, which are common targets for compliance violations under these regulations.

Mitigation Strategies

Upgrade GestSup to version 3.2.62 or later immediately. Monitor incoming emails for suspicious nested MIME encoded-words in subjects. Disable the IMAP OAuth connector if not essential until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102374. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart