CVE-2026-22196
GestSup < 3.2.60 SQL Injection in Ticket Creation
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in ticket creation functionality. User-controlled input provided during ticket creation is incorporated into SQL queries without sufficient neutralization, allowing an authenticated attacker to manipulate database queries. Successful exploitation can result in unauthorized access to or modification of database contents depending on database privileges.
| CWE | CWE-89 |
| Vendor | gestsup |
| Product | gestsup |
| Published | Jan 9, 2026 |
| Last Updated | Mar 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for gestsup gestsup
Be the first to know when new unknown vulnerabilities affecting gestsup gestsup are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
GestSup / GestSup
0 < 3.2.60
References
Credits
Geoffrey Robert and Valentin Holubec of Akailabs VulnCheck