{"id":"CVE-2026-102374","published":"2026-09-29T01:16:44.900","lastModified":"2026-09-29T11:16:42.423","description":"GestSup versions before 3.2.62 contain a stored cross-site scripting vulnerability in the IMAP OAuth connector that double-decodes MIME-encoded email subjects after HTML escaping. Unauthenticated attackers can send crafted emails to monitored mailboxes with nested MIME encoded-words to inject JavaScript that executes in technician sessions when viewing tickets.","cvssScore":6.1,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://gestsup.fr/index.php?page=changelog","tags":[]},{"url":"https://gestsup.fr/index.php?page=download","tags":[]},{"url":"https://gestsup.fr/index.php?page=download&channel=stable&version=3.2.62&type=patch","tags":[]},{"url":"https://www.vulncheck.com/advisories/gestsup-before-3.2.62-stored-xss-via-double-decoded-email-subject-in-oauth-imap-connector","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}