CVE-2026-22197 Details
Description
GestSup versions prior to 3.2.60 contain multiple SQL injection vulnerabilities in the asset list functionality. Multiple request parameters used to filter, search, or sort assets are incorporated into SQL queries without sufficient neutralization, allowing an authenticated attacker to manipulate database queries. Successful exploitation can result in unauthorized access to or modification of database contents depending on database privileges.
A series of SQL injection vulnerabilities have been identified in GestSup versions up to and including 3.2.56. These vulnerabilities reside within the asset list feature, where several request parameters used for filtering, searching, or sorting assets are directly included in SQL queries without adequate sanitization. This oversight enables authenticated attackers to manipulate database queries, potentially leading to unauthorized access to or modification of database contents, depending on their database privileges.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gestsup.fr/index.php?page=changelog | [email protected] | Release Notes |
| https://www.vulncheck.com/advisories/gestsup-multiple-sqli-in-asset-list | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gestsup gestsup | <= 3.2.56 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 14, 2026 | Initial Analysis | [email protected] |
| Jan 14, 2026 | CVE Modified | [email protected] |
| Jan 9, 2026 | New CVE Received | [email protected] |