Freescout

Freescout

81 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.24%
  • Veröffentlicht 30.05.2025 06:30:07
  • Zuletzt bearbeitet 04.06.2025 19:57:05

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, deleting the file .htaccess allows an attacker to upload an HTML file containing malicious JavaScript code to the server, which can result in a Cross-Site Scripti...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 30.05.2025 06:27:23
  • Zuletzt bearbeitet 04.06.2025 18:32:36

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, when an administrative account is a deleting a user, there is the the possibility of a race condition occurring. This issue has been patched in version 1.8.181.

Exploit
  • EPSS 0.23%
  • Veröffentlicht 30.05.2025 06:26:24
  • Zuletzt bearbeitet 04.06.2025 19:54:12

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, the system's incorrect validation of last_name and first_name during profile data updates allows for the injection of arbitrary JavaScript code, which will be exe...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 30.05.2025 06:18:01
  • Zuletzt bearbeitet 04.06.2025 19:56:57

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to insufficient data validation and sanitization during data reception. This issue has bee...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 30.05.2025 06:17:28
  • Zuletzt bearbeitet 04.06.2025 19:57:13

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when creating a translation of a phrase that appears in a flash-message after a completed action, it is possible to inject a payload to exploit XSS vulnerability....

Exploit
  • EPSS 0.24%
  • Veröffentlicht 30.05.2025 06:17:08
  • Zuletzt bearbeitet 04.06.2025 19:57:20

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the cross-site scripiting (XSS) vulnerability is caused by the lack of input validation and sanitization in both \Session::flash and __, allowing user input to be...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 30.05.2025 06:16:50
  • Zuletzt bearbeitet 04.06.2025 14:32:26

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data when an authenticated us...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 30.05.2025 04:59:23
  • Zuletzt bearbeitet 04.06.2025 15:34:51

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data in the conversation POST...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 30.05.2025 04:58:48
  • Zuletzt bearbeitet 04.06.2025 15:35:21

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data during mail signature sa...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 30.05.2025 04:35:30
  • Zuletzt bearbeitet 04.06.2025 15:35:32

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, there is a mass assignment vulnerability. The Customer object is updated using the fill() method, which processes fields such as channel and channel_id. However, ...