PT-2026-2167 · Gestsup · Gestsup
Geoffrey Robert
+2
·
Published
2026-01-09
·
Updated
2026-01-09
·
CVE-2026-22194
CVSS v4.0
8.9
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
GestSup versions up to and including 3.2.56
Description
The application does not verify the authenticity of client requests, leading to a cross-site request forgery condition. An attacker can potentially trick a logged-in user into submitting malicious requests, allowing the attacker to perform actions with the user's permissions. Specifically, this can be used to create privileged accounts by targeting the administrative user creation endpoint ''/admin/createUser''. The
createUser() function is vulnerable to this attack.Recommendations
Versions prior to 3.2.56 are recommended to be used.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gestsup