Freescout

Freescout

72 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 21.04.2026 17:16:57
  • Zuletzt bearbeitet 22.04.2026 21:10:14

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, `MailboxesController::updateSave()` persists `chat_start_new` outside the allowed-field filter. A user with only the mailbox `sig` permission sees only the signat...

  • EPSS 0.21%
  • Veröffentlicht 21.04.2026 17:16:57
  • Zuletzt bearbeitet 22.04.2026 21:10:14

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, when `APP_SHOW_ONLY_ASSIGNED_CONVERSATIONS` is enabled, direct conversation view correctly blocks users who are neither the assignee nor the creator. The `save_dr...

  • EPSS 0.22%
  • Veröffentlicht 21.04.2026 17:16:57
  • Zuletzt bearbeitet 22.04.2026 21:10:14

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, customer-thread editing is authorized through `ThreadPolicy::edit()`, which checks mailbox access but does not apply the assigned-only restriction from `Conversat...

  • EPSS 0.22%
  • Veröffentlicht 21.04.2026 17:16:57
  • Zuletzt bearbeitet 22.04.2026 21:10:14

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the assigned-only restriction is applied to direct conversation view and folder queries, but not to non-folder query builders. Global search and the AJAX filter p...

  • EPSS 0.21%
  • Veröffentlicht 21.04.2026 17:16:56
  • Zuletzt bearbeitet 22.04.2026 21:10:14

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the phone-conversation creation flow accepts attacker-controlled `customer_id`, `name`, `to_email`, and `phone` values and resolves the target customer in the bac...

  • EPSS 0.24%
  • Veröffentlicht 21.04.2026 17:16:56
  • Zuletzt bearbeitet 22.04.2026 21:10:14

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, a low-privileged agent can edit a visible customer and add an email address already owned by a hidden customer in another mailbox. The server discloses the hidden...

  • EPSS 0.21%
  • Veröffentlicht 21.04.2026 17:16:56
  • Zuletzt bearbeitet 22.04.2026 21:10:14

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the Change Customer modal exposes a “Create a new customer” flow via POST /customers/ajax with action=create. Under limited visibility, the endpoint drops unique-...

  • EPSS 0.25%
  • Veröffentlicht 21.04.2026 17:16:55
  • Zuletzt bearbeitet 22.04.2026 21:10:14

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, the `load_customer_info` action in `POST /conversation/ajax` returns complete customer profile data to any authenticated user without verifying mailbox access. An...

  • EPSS 0.3%
  • Veröffentlicht 21.04.2026 17:16:55
  • Zuletzt bearbeitet 22.04.2026 21:10:14

FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a mass assignment vulnerability in the mailbox connection settings endpoints of FreeScout (`connectionIncomingSave()` at `app/Http/Controllers/MailboxesContr...

  • EPSS 0.12%
  • Veröffentlicht 21.04.2026 17:16:50
  • Zuletzt bearbeitet 22.04.2026 21:08:48

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the mailbox OAuth disconnect action is implemented as `GET /mailbox/oauth-disconnect/{id}/{in_out}/{provider}`. It removes stored OAuth metadata from the mailbox ...