GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 25 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to monitored mailboxes, which are written to the web-accessible upload/ticket directory and executed when accessed. | |
| Title | GestSup before 3.2.61 Remote Code Execution via IMAP Attachment | |
| First Time appeared |
Gestsup
Gestsup gestsup |
|
| Weaknesses | CWE-434 | |
| CPEs | cpe:2.3:a:gestsup:gestsup:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gestsup
Gestsup gestsup |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-25T20:13:07.623Z
Reserved: 2026-09-25T19:47:52.073Z
Link: CVE-2026-100389
No data.
Status : Received
Published: 2026-09-25T21:17:22.483
Modified: 2026-09-25T21:17:22.483
Link: CVE-2026-100389
No data.
OpenCVE Enrichment
No data.
Weaknesses