No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 30 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed. | GestSup versions before 3.2.62 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed. |
| Title | GestSup before 3.2.61 Remote Code Execution via IMAP Attachment | GestSup before 3.2.62 Remote Code Execution via IMAP Attachment |
| References |
|
Tue, 29 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 25 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed. | |
| Title | GestSup before 3.2.61 Remote Code Execution via IMAP Attachment | |
| First Time appeared |
Gestsup
Gestsup gestsup |
|
| Weaknesses | CWE-434 | |
| CPEs | cpe:2.3:a:gestsup:gestsup:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gestsup
Gestsup gestsup |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-30T11:15:12.444Z
Reserved: 2026-09-25T19:47:52.073Z
Link: CVE-2026-100389
Updated: 2026-09-29T18:21:16.573Z
Status : Received
Published: 2026-09-25T21:17:22.483
Modified: 2026-09-30T12:17:10.390
Link: CVE-2026-100389
No data.
OpenCVE Enrichment
Updated: 2026-09-30T13:15:19Z