FreeScout
45 exploits
Active since Mar 2024
FreeScout has Authentication Bypass and Information Disclosure in SystemController via /system/cron
CVSS 9.8
FreeScout has Stored XSS / CSS Injection via linkify() — Unescaped URL in Anchor href
CVSS 6.1
FreeScout vulnerable to SSRF via IMAP/SMTP Connection Test Endpoints
CVSS 4.1
FreeScout has HTML Injection in Outgoing Emails via Unsanitized Customer Name in Signature Variables
CVSS 5.8
FreeScout Vulnerable to XSS via Mailbox Signature Due to Incomplete HTML Sanitization
CVSS 8.5
FreeScout's Mass Assignment in Mailbox Connection Settings Enables Silent Email Exfiltration
CVSS 9.0
FreeScout's Missing Authorization in load_customer_info Allows Any Authenticated User to Access Full Customer PII
FreeScout has Customer Edit Cross-Mailbox Email Takeover
CVSS 7.6
FreeScout's Customer AJAX Create Modifies Hidden Existing Customer
CVSS 4.3
FreeScout: Improper Authorization in Phone Conversation Creation Enables Cross-Mailbox Hidden Customer Modification
CVSS 7.1
FreeScout's cross-user undo reply allows mailbox peers to recall another agent's outbound reply
CVSS 5.9
FreeScout allows non-folder conversation queries to disclose assigned-only hidden conversations
CVSS 4.3
FreeScout has assigned-only visibility bypass that allows editing hidden customer-authored threads
CVSS 7.1
FreeScout has assigned-only visibility bypass via save_draft that allows hidden conversation draft injection
CVSS 7.1
FreeScout's signature only mailbox permission allows unauthorized mailbox chat setting changes
CVSS 7.1
FreeScout's client-controlled attachment IDs allow deletion of existing conversation attachments
CVSS 7.1
FreeScout has Zip Slip path traversal in module installation that allows arbitrary file write leading to RCE
CVSS 9.1
FreeScout's Mailbox OAuth disconnect uses a state-changing GET and is CSRFable
CVSS 5.4
FreeScout has Predictable Attachment Token that Allows Unauthenticated Private File Download via Brute Force
CVSS 9.1
FreeScout Vulnerable to CSS Injection via Stored Style Tag in Mailbox Signature (CSRF Token Exfiltration)
CVSS 8.1
FreeScout Customer Merge Cross-Mailbox Authorization Bypass
CVSS 7.6
FreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScout
CVSS 5.4
FreeScout: SSRF protection bypass via broken CIDR check in checkIpByMask()
CVSS 5.3
FreeScout: Broken Access Control in ThreadPolicy — Any User Can Read/Edit All Customer Messages
FreeScout: Stored XSS through SVG file upload with filter bypass