FreeScout
46 exploits
Active since Mar 2024
FreeScout: Stored XSS through SVG file upload with filter bypass
FreeScout: Stored XSS via Unescaped Email Template Rendering ({!! $thread->body !!})
CVSS 9.3
FreeScout <=1.8.206 - Authenticated RCE
CVSS 10.0
FreeScout < 1.8.206 - Authenticated Remote Code Execution via .htaccess Upload
CVSS 8.8
FreeScout < 1.8.206 - Predictable Token Authentication Bypass via MD5 Token
CVSS 9.8
freescout < 1.8.124 - Sensitive Information Disclosure via Conversation Send Log Endpoint
CVSS 7.1
FreeScout < 1.8.139 - Unauthenticated Stored HTML Injection in Email Receival Module
CVSS 7.6
FreeScout < 1.8.139 - Prototype Pollution via getQueryParam Function
CVSS 4.6
FreeScout <1.8.178 - Code Injection
CVSS 6.5
FreeScout <1.8.178 - Deserialization
CVSS 7.2
FreeScout <1.8.178 - Code Injection
CVSS 7.2
freescout < 1.8.179 - Remote Code Execution via Unrestricted File Upload
CVSS 9.8
FreeScout <1.8.179 - Privilege Escalation
CVSS 8.1
FreeScout <1.8.179 - Info Disclosure
CVSS 4.3
freescout < 1.8.180 - Incorrect Authorization via Conversation Assignment
CVSS 8.1
FreeScout <1.8.180 - Info Disclosure
CVSS 8.1
FreeScout <1.8.180 - Mass Assignment
CVSS 4.9
freescout < 1.8.181 - Stored Cross-Site Scripting via Profile Name Fields
CVSS 5.4
FreeScout <1.8.181 - Privilege Escalation
CVSS 6.6
freescout < 1.8.86 - Authenticated Remote Code Execution via Unsafe Deserialization in Helper::decrypt()
CVSS 8.8
FreeScout < 1.8.186 - Authenticated Remote Code Execution via Untrusted Data Deserialization in Decrypt Function
CVSS 8.8