rootpwn

medium · CVSS v3 6.1

CVE-2026-102374

GestSup versions before 3.2.62 contain a stored cross-site scripting vulnerability in the IMAP OAuth connector that doub…

Description

GestSup versions before 3.2.62 contain a stored cross-site scripting vulnerability in the IMAP OAuth connector that double-decodes MIME-encoded email subjects after HTML escaping. Unauthenticated attackers can send crafted emails to monitored mailboxes with nested MIME encoded-words to inject JavaScript that executes in technician sessions when viewing tickets.

Scores

Severity
medium
CVSS v2
6.4
CVSS v3
6.1
CVSS v4
—
EPSS
—

← All CVEs