Freescout

Freescout

72 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 29.05.2026 19:52:22
  • Zuletzt bearbeitet 02.06.2026 03:16:17

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset endpoint returns visually distinct responses depending on whether the submitted email address belongs to an existing user account,...

  • EPSS 0.15%
  • Veröffentlicht 29.05.2026 19:51:41
  • Zuletzt bearbeitet 02.06.2026 03:16:18

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.220, the email processing pipeline in FreeScout's FetchEmails command has two code paths for identifying agent (user) replies based on In-Reply-To / Refer...

  • EPSS 0.16%
  • Veröffentlicht 29.05.2026 19:48:38
  • Zuletzt bearbeitet 01.06.2026 19:16:54

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, while investigating the ThreadPolicy::delete issue reported previously, the same missing mailbox membership check was found in the sibling ThreadPoli...

  • EPSS 0.16%
  • Veröffentlicht 29.05.2026 19:47:46
  • Zuletzt bearbeitet 01.06.2026 17:17:34

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, FreeScout allows a non-admin user to permanently delete an internal note (private thread) from any conversation, even after that user's access to the...

  • EPSS 0.17%
  • Veröffentlicht 07.05.2026 18:09:23
  • Zuletzt bearbeitet 08.05.2026 15:16:43

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.214, the Change Customer modal correctly hides out-of-scope customers through the mailbox-filtered search endpoint, but the backend conversation_c...

  • EPSS 0.21%
  • Veröffentlicht 07.05.2026 18:08:09
  • Zuletzt bearbeitet 07.05.2026 21:16:29

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::sanitizeRemoteUrl() in app/Misc/Helper.php follows HTTP redirects via curlGetLastRedirectedUrl() but then re-validates the original U...

  • EPSS 0.17%
  • Veröffentlicht 07.05.2026 18:05:43
  • Zuletzt bearbeitet 07.05.2026 20:16:43

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with updateAutoReply permission can store an XSS payload in the mailbox auto-reply message. The payload is rendered unescaped in the a...

  • EPSS 0.25%
  • Veröffentlicht 07.05.2026 18:03:50
  • Zuletzt bearbeitet 08.05.2026 22:16:30

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-setup/{hash} endpoint accepts a 60-character random invite_hash to set a new user's password. The endpoint performs no expiration c...

  • EPSS 0.26%
  • Veröffentlicht 07.05.2026 18:02:01
  • Zuletzt bearbeitet 07.05.2026 19:51:36

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user holding the PERM_EDIT_USERS permission (intended for general user-profile editing) can read and modify the notification subscriptions ...

  • EPSS 0.24%
  • Veröffentlicht 21.04.2026 17:16:57
  • Zuletzt bearbeitet 22.04.2026 21:10:14

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route `GET /conversation/undo-reply/{thread_id}` checks only whether the current user can view the parent conversation. It does not verify that the ...