PT-2026-2171 · Gestsup · Gestsup

Geoffrey Robert

+2

·

Publicado

2026-01-09

·

Atualizado

2026-01-09

·

CVE-2026-22198

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GestSup versions up to and including 3.2.56
Description GestSup versions up to and including 3.2.56 contain a pre-authentication stored cross-site scripting (XSS) issue in the API error logging functionality. An unauthenticated attacker can inject attacker-controlled HTML/JavaScript into log entries by sending a crafted API request with a malicious X-API-KEY header value to the /api/v1/ticket.php endpoint. When an administrator views the affected logs in the web interface, the injected content is rendered without proper output encoding, leading to arbitrary script execution in the administrator’s browser session.
Recommendations GestSup versions prior to 3.2.56 should be updated.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-22198

Produtos afetados

Gestsup