天下漏洞,尽知其名
MEDIUM

CVE-2026-102373 GestSup 授权绕过漏洞

原始情报

GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in thread.php. Authenticated attackers can enumerate sequential comment IDs to read private comments from other users’ tickets without proper authorization checks.