CVE-2026-22195: GestSup < 3.2.60 SQL Injection in Search Bar
GestSup versions prior to 3.2.60 contain a SQL injection vulnerability in the search bar functionality. User-controlled search input is incorporated into SQL queries without sufficient neutralization, allowing an authenticated attacker to manipulate database queries. Successful exploitation can result in unauthorized access to or modification of database contents depending on database privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22195?
CVE-2026-22195 is classified as a high severity SQL injection vulnerability that can allow authenticated attackers to manipulate database queries.
How do I fix CVE-2026-22195?
To fix CVE-2026-22195, update GestSup to version 3.2.57 or later, which includes mitigations for this vulnerability.
What versions of GestSup are affected by CVE-2026-22195?
CVE-2026-22195 affects GestSup versions up to and including 3.2.56.
What could an attacker achieve by exploiting CVE-2026-22195?
An attacker exploiting CVE-2026-22195 could potentially manipulate database queries, leading to unauthorized data access or modification.
Is user authentication required to exploit CVE-2026-22195?
Yes, exploitation of CVE-2026-22195 requires user authentication to access the vulnerable search functionality.