Freescout

Freescout

80 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.28%
  • Veröffentlicht 31.03.2026 21:28:16
  • Zuletzt bearbeitet 24.07.2026 21:10:00

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, checkIpByMask() in app/Misc/Helper.php checks whether the input IP contains a / character. Plain IP addresses never contain /, so the functio...

Exploit
  • EPSS 0.53%
  • Veröffentlicht 19.03.2026 21:35:17
  • Zuletzt bearbeitet 23.03.2026 19:14:38

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.208 and below are vulnerable to Stored Cross-Site Scripting (XSS) through FreeScout's email notification templates. Incoming email bodies are stored in th...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 19.03.2026 21:26:09
  • Zuletzt bearbeitet 23.03.2026 19:25:21

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, bypasses of the attachment view logic and SVG sanitizer make it possible to upload and render an SVG that runs malicious JavaScript. An ...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 19.03.2026 21:21:54
  • Zuletzt bearbeitet 23.03.2026 19:30:28

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, the ThreadPolicy::edit() method contains a broken access control vulnerability that allows any authenticated user (regardless of role or...

Medienbericht Exploit
  • EPSS 31.12%
  • Veröffentlicht 03.03.2026 22:59:08
  • Zuletzt bearbeitet 11.03.2026 19:29:44

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with file upload permissions to achieve Remote Code Exec...

Exploit
  • EPSS 0.67%
  • Veröffentlicht 25.02.2026 04:16:04
  • Zuletzt bearbeitet 26.02.2026 16:08:44

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's `TokenAuth` middleware uses a predictable authentication token computed as `MD5(user_id + created_at + APP_KEY)`. This token is s...

Medienbericht Exploit
  • EPSS 2.12%
  • Veröffentlicht 25.02.2026 04:16:03
  • Zuletzt bearbeitet 26.02.2026 16:07:11

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's file upload restriction list in `app/Misc/Helper.php` does not include `.htaccess` or `.user.ini` files. On Apache servers with `...

Exploit
  • EPSS 0.72%
  • Veröffentlicht 03.09.2025 01:34:16
  • Zuletzt bearbeitet 08.09.2025 15:03:47

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Versions 1.8.185 and earlier contain a deserialization of untrusted data vulnerability that allows authenticated attackers with knowledge of the application's APP_KEY ...

Exploit
  • EPSS 0.98%
  • Veröffentlicht 26.07.2025 03:35:17
  • Zuletzt bearbeitet 11.09.2025 15:54:46

FreeScout is a lightweight free open source help desk and shared inbox built with PHP (Laravel framework). In versions 1.8.185 and below, there is a critical deserialization vulnerability in the /conversation/ajax endpoint that allows authenticated u...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 30.05.2025 06:30:07
  • Zuletzt bearbeitet 04.06.2025 19:57:05

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, deleting the file .htaccess allows an attacker to upload an HTML file containing malicious JavaScript code to the server, which can result in a Cross-Site Scripti...