HarborGuard / CVE
Back to search
HIGHCVE-2026-22197Published Modified CNA VulnCheck

CVE-2026-22197: GestSup < 3.2.60 Multiple SQL Injections in Asset List

GestSup versions prior to 3.2.60 contain multiple SQL injection vulnerabilities in the asset list functionality. Multiple request parameters used to filter, search, or sort assets are incorporated into SQL queries without sufficient neutralization, allowing an authenticated attacker to manipulate database queries. Successful exploitation can result in unauthorized access to or modification of database contents depending on database privileges.

Metrics

CVSS v4.0
7.5
Severity
HIGH
Fixed in
3.2.60
Affected Products
1

Fix available

3.2.60
Affected packages
  • GestSup / GestSup
    < 3.2.60 (from 0)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVE-2026-22197: GestSup < 3.2.60 Multiple SQL Injections in Asset List | HarborGuard CVE