关键漏洞信息 漏洞标题 GestSup < 3.2.60 SQL Injection in Ticket Creation 严重性 HIGH 影响版本 GestSup < 3.2.60 日期 January 9, 2026 CWE ID CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVSS Score W:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 描述 GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in ticket creation functionality. User-controlled input provided during ticket creation is incorporated into SQL queries without sufficient neutralization, allowing an authenticated attacker to manipulate database queries. Successful exploitation can result in unauthorized access to or modification of database contents depending on database privileges. 参考链接 GestSup Change Log 发现者 Geoffrey Robert and Valentin Holubec of Akailabs