PT-2026-2171 · Gestsup · Gestsup
Geoffrey Robert
+2
·
Published
2026-01-09
·
Updated
2026-01-09
·
CVE-2026-22198
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GestSup versions up to and including 3.2.56
Description
GestSup versions up to and including 3.2.56 contain a pre-authentication stored cross-site scripting (XSS) issue in the API error logging functionality. An unauthenticated attacker can inject attacker-controlled HTML/JavaScript into log entries by sending a crafted API request with a malicious
X-API-KEY header value to the /api/v1/ticket.php endpoint. When an administrator views the affected logs in the web interface, the injected content is rendered without proper output encoding, leading to arbitrary script execution in the administrator’s browser session.Recommendations
GestSup versions prior to 3.2.56 should be updated.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gestsup