PT-2026-2171 · Gestsup · Gestsup
Geoffrey Robert
+2
·
Publicado
2026-01-09
·
Atualizado
2026-01-09
·
CVE-2026-22198
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GestSup versions up to and including 3.2.56
Description
GestSup versions up to and including 3.2.56 contain a pre-authentication stored cross-site scripting (XSS) issue in the API error logging functionality. An unauthenticated attacker can inject attacker-controlled HTML/JavaScript into log entries by sending a crafted API request with a malicious
X-API-KEY header value to the /api/v1/ticket.php endpoint. When an administrator views the affected logs in the web interface, the injected content is rendered without proper output encoding, leading to arbitrary script execution in the administrator’s browser session.Recommendations
GestSup versions prior to 3.2.56 should be updated.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Gestsup