{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/gestsup--3.2.61/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:gestsup:gestsup:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-100389"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GestSup (\u003c 3.2.61)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","web-application","vulnerability"],"_cs_type":"advisory","_cs_vendors":["GestSup"],"content_html":"\u003cp\u003eGestSup versions prior to 3.2.61 contain a critical remote code execution (RCE) vulnerability located within the basic IMAP connector's attachment handling logic. The vulnerability exists because the software fails to properly validate or filter blocked file extensions when processing incoming emails for support tickets.\u003c/p\u003e\n\u003cp\u003eAn unauthenticated attacker can exploit this flaw by sending an email containing a malicious PHP script as an attachment to a mailbox monitored by the GestSup IMAP connector. The application subsequently saves this attachment directly to a web-accessible directory, specifically the upload/ticket folder. By navigating to the URL of the uploaded file, an attacker can trigger the execution of the PHP script, gaining unauthorized code execution on the underlying server. This flaw poses a high risk to organizations relying on the IMAP integration for automated ticket creation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary code on the web server hosting GestSup. This can lead to full system compromise, data theft from the ticketing system, and potential lateral movement into the internal network environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade GestSup to version 3.2.61 or later to implement proper file extension validation.\u003c/li\u003e\n\u003cli\u003eRestrict access to the upload/ticket directory via web server configuration to prevent direct execution of PHP or other script files.\u003c/li\u003e\n\u003cli\u003eAudit the upload/ticket directory for any unauthorized PHP files or anomalous scripts that may have been uploaded via the IMAP connector.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-25T22:55:31Z","date_published":"2026-09-25T22:55:31Z","id":"https://feed.craftedsignal.io/briefs/2026-09-gestsup-rce/","summary":"GestSup versions before 3.2.61 are vulnerable to unauthenticated remote code execution via malicious file attachments in the IMAP connector.","title":"Remote Code Execution in GestSup IMAP Connector","url":"https://feed.craftedsignal.io/briefs/2026-09-gestsup-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - GestSup (\u003c 3.2.61)","version":"https://jsonfeed.org/version/1.1"}