GestSup versions before 3.2.62 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed.

Project Subscriptions

Vendors Products
Gestsup Subscribe
Gestsup Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 30 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed. GestSup versions before 3.2.62 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed.
Title GestSup before 3.2.61 Remote Code Execution via IMAP Attachment GestSup before 3.2.62 Remote Code Execution via IMAP Attachment
References

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 25 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed.
Title GestSup before 3.2.61 Remote Code Execution via IMAP Attachment
First Time appeared Gestsup
Gestsup gestsup
Weaknesses CWE-434
CPEs cpe:2.3:a:gestsup:gestsup:*:*:*:*:*:*:*:*
Vendors & Products Gestsup
Gestsup gestsup
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-30T11:15:12.444Z

Reserved: 2026-09-25T19:47:52.073Z

Link: CVE-2026-100389

cve-icon Vulnrichment

Updated: 2026-09-29T18:21:16.573Z

cve-icon NVD

Status : Received

Published: 2026-09-25T21:17:22.483

Modified: 2026-09-30T12:17:10.390

Link: CVE-2026-100389

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T13:15:19Z

Weaknesses