Freescout

Freescout

72 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.29%
  • Veröffentlicht 30.05.2025 04:35:30
  • Zuletzt bearbeitet 04.06.2025 15:35:32

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, there is a mass assignment vulnerability. The Customer object is updated using the fill() method, which processes fields such as channel and channel_id. However, ...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 30.05.2025 04:35:03
  • Zuletzt bearbeitet 04.06.2025 15:35:47

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an attacker with an unactivated email invitation containing invite_hash, can exploit this vulnerability to self-activate their account, despite it being blocked o...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 30.05.2025 04:34:34
  • Zuletzt bearbeitet 04.06.2025 15:35:54

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an authorized user with the administrator role or with the privilege User::PERM_EDIT_USERS can create a user, specifying the path to the user's avatar ../.htacces...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 30.05.2025 04:34:09
  • Zuletzt bearbeitet 04.06.2025 15:36:04

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the laravel-translation-manager package does not correctly validate user input, enabling the deletion of any directory, given sufficient access rights. This issue...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 30.05.2025 04:32:12
  • Zuletzt bearbeitet 04.06.2025 15:36:13

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, insufficient input validation during user creation has resulted in a mass assignment vulnerability, allowing an attacker to manipulate all fields of the object, w...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 30.05.2025 04:31:42
  • Zuletzt bearbeitet 04.06.2025 15:36:20

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application's logic requires the user to perform a correct sequence of actions to implement a functional capability, but the application allows access to the ...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 30.05.2025 04:30:09
  • Zuletzt bearbeitet 04.06.2025 15:36:28

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when adding and editing user records using the fill() method, there is no check for the absence of the password field in the data coming from the user, which lead...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 29.05.2025 16:27:43
  • Zuletzt bearbeitet 02.07.2025 15:49:05

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the System does not provide a check on which "clients" of the System an authorized user can view and edit, and which ones they cannot. As a result, an authorized ...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 29.05.2025 15:55:47
  • Zuletzt bearbeitet 02.07.2025 15:50:57

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application incorrectly checks user access rights for conversations. Users with show_only_assigned_conversations enabled can assign themselves to an arbitrary...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 29.05.2025 15:27:52
  • Zuletzt bearbeitet 11.07.2025 15:28:46

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, when creating a conversation from a message in another conversation, there is no check to ensure that the user has the ability to view this message. Thus, the use...