CVE-2025-48390
- EPSS 0.83%
- Veröffentlicht 29.05.2025 15:15:03
- Zuletzt bearbeitet 11.07.2025 15:28:18
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to code injection due to insufficient validation of user input in the php_path parameter. The backticks characters are not removed, as wel...
CVE-2025-48389
- EPSS 0.85%
- Veröffentlicht 29.05.2025 15:12:16
- Zuletzt bearbeitet 11.07.2025 15:26:53
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to deserialization of untrusted data due to insufficient validation. Through the set function, a string with a serialized object can be pa...
CVE-2025-48388
- EPSS 0.36%
- Veröffentlicht 29.05.2025 09:16:25
- Zuletzt bearbeitet 11.07.2025 15:22:53
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application performs insufficient validation of user-supplied data, which is used as arguments to string formatting functions. As a result, an attacker can pa...
CVE-2023-52268
- EPSS 0.62%
- Veröffentlicht 12.11.2024 19:15:07
- Zuletzt bearbeitet 15.04.2026 00:35:42
The End-User Portal module before 1.0.65 for FreeScout sometimes allows an attacker to authenticate as an arbitrary user because a session token can be sent to the /auth endpoint. NOTE: this module is not part of freescout-helpdesk/freescout on GitHu...
CVE-2024-34698
- EPSS 0.46%
- Veröffentlicht 14.05.2024 15:39:27
- Zuletzt bearbeitet 10.01.2025 15:11:33
FreeScout is a free, self-hosted help desk and shared mailbox. Versions of FreeScout prior to 1.8.139 contain a Prototype Pollution vulnerability in the `/public/js/main.js` source file. The Prototype Pollution arises because the `getQueryParam` Func...
CVE-2024-34697
- EPSS 0.58%
- Veröffentlicht 14.05.2024 15:39:27
- Zuletzt bearbeitet 10.01.2025 15:13:34
FreeScout is a free, self-hosted help desk and shared mailbox. A stored HTML Injection vulnerability has been identified in the Email Receival Module of the Freescout Application. The vulnerability allows attackers to inject malicious HTML content in...
- EPSS 1.73%
- Veröffentlicht 22.03.2024 17:15:08
- Zuletzt bearbeitet 10.01.2025 15:03:50
FreeScout is a self-hosted help desk and shared mailbox. Versions prior to 1.8.128 are vulnerable to OS Command Injection in the /public/tools.php source file. The value of the php_path parameter is being executed as an OS command by the shell_exec f...
- EPSS 0.86%
- Veröffentlicht 22.03.2024 17:15:08
- Zuletzt bearbeitet 10.01.2025 15:06:59
FreeScout is a self-hosted help desk and shared mailbox. A Stored Cross-Site Scripting (XSS) vulnerability has been identified within the Signature Input Field of the FreeScout Application prior to version 1.8.128. Stored XSS occurs when user input i...
CVE-2024-28186
- EPSS 0.55%
- Veröffentlicht 12.03.2024 20:15:08
- Zuletzt bearbeitet 10.01.2025 15:01:40
FreeScout is an open source help desk and shared inbox built with PHP. A vulnerability has been identified in the Free Scout Application, which exposes SMTP server credentials used by an organization in the application to users of the application. T...
CVE-2024-1932
- EPSS 0.38%
- Veröffentlicht 28.02.2024 00:15:54
- Zuletzt bearbeitet 10.01.2025 14:55:25
Unrestricted Upload of File with Dangerous Type in freescout-helpdesk/freescout