PT-2026-99109 · Gestsup · Gestsup
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GestSup versions prior to 3.2.61
Description
An issue exists in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails containing PHP attachments to monitored mailboxes. These files are then written to the web-accessible
upload/ticket directory and can be executed upon access, leading to remote code execution.Recommendations
Update GestSup to version 3.2.61 or later.
Exploit
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gestsup