HarborGuard / CVE
Back to search
HIGHCVE-2026-22194Published Modified CNA VulnCheck

CVE-2026-22194: GestSup <= 3.2.60 CSRF Allows Privileged Actions

GestSup versions up to and including 3.2.60 contain a cross-site request forgery (CSRF) vulnerability where the application does not verify the authenticity of client requests. An attacker can induce a logged-in user to submit crafted requests that perform actions with the victim's privileges. This can be exploited to create privileged accounts by targeting the administrative user creation endpoint.

Metrics

CVSS v4.0
8.9
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • GestSup / GestSup
    ≤ 3.2.60
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:H/SA:H