← All reports

FreeScout versions prior to 1.8.213 are vulnerable to Server-Side Request Forgery (SSRF) and arbitrary HTML injection in outgoing emails, which could allow attackers to exploit the system.

CybersecurityTechnologyConflictApr 21, 2026score 0.172 posts Β· 0 replies across 1 instances
The thread discusses two vulnerabilities in the FreeScout help desk software, both related to security issues that could allow attackers to exploit the system. These vulnerabilities highlight the importance of software security updates and the risks associated with unpatched systems.

Claims

FreeScout versions prior to 1.8.213 are vulnerable to Server-Side Request Forgery (SSRF) and arbitrary HTML injection in outgoing emails, which could allow attackers to exploit the system.
Parent: Software SecurityEntity: FreeScoutImpact: negativeDate: Apr 21, 2026Target: FreeScout's security practices and software updates

Source posts

@[email protected]
🚨 EUVD-2026-24167 πŸ“Š Score: 4.1/10 (CVSS v3.1) πŸ“¦ Product: freescout 🏒 Vendor: freescout-help-desk πŸ“… Updated: 2026-04-21 πŸ“ FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a Server-Side Request Forgery (SSRF) vulnerability in the IMAP/SMTP connection test functionality of FreeScout's `MailboxesController`. Three AJAX acti... πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24167 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts Β· 0 favs Β· 0 replies Β· Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
🚨 EUVD-2026-24168 πŸ“Š Score: 5.8/10 (CVSS v3.1) πŸ“¦ Product: freescout 🏒 Vendor: freescout-help-desk πŸ“… Updated: 2026-04-21 πŸ“ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can inject arbitrary HTML into outgoing emails generated by FreeScout by sending an email with a crafted From display name. The ... πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24168 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts Β· 0 favs Β· 0 replies Β· Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
🚨 EUVD-2026-24187 πŸ“Š Score: 7.1/10 (CVSS v3.1) πŸ“¦ Product: freescout 🏒 Vendor: freescout-help-desk πŸ“… Updated: 2026-04-21 πŸ“ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the phone-conversation creation flow accepts attacker-controlled `customer_id`, `name`, `to_email`, and `phone` values and resolves the target customer in t... πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24187 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts Β· 0 favs Β· 0 replies Β· Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
🚨 EUVD-2026-24189 πŸ“Š Score: 5.9/10 (CVSS v3.1) πŸ“¦ Product: freescout 🏒 Vendor: freescout-help-desk πŸ“… Updated: 2026-04-21 πŸ“ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route `GET /conversation/undo-reply/{thread_id}` checks only whether the current user can view the parent conversation. It does not verify tha... πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24189 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts Β· 0 favs Β· 0 replies Β· Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
🚨 EUVD-2026-24191 πŸ“Š Score: 4.3/10 (CVSS v3.1) πŸ“¦ Product: freescout 🏒 Vendor: freescout-help-desk πŸ“… Updated: 2026-04-21 πŸ“ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the assigned-only restriction is applied to direct conversation view and folder queries, but not to non-folder query builders. Global search and the AJAX fi... πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24191 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts Β· 0 favs Β· 0 replies Β· Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
🚨 EUVD-2026-24193 πŸ“Š Score: 7.1/10 (CVSS v3.1) πŸ“¦ Product: freescout 🏒 Vendor: freescout-help-desk πŸ“… Updated: 2026-04-21 πŸ“ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, customer-thread editing is authorized through `ThreadPolicy::edit()`, which checks mailbox access but does not apply the assigned-only restriction from `Con... πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24193 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts Β· 0 favs Β· 0 replies Β· Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
🚨 EUVD-2026-24195 πŸ“Š Score: 7.1/10 (CVSS v3.1) πŸ“¦ Product: freescout 🏒 Vendor: freescout-help-desk πŸ“… Updated: 2026-04-21 πŸ“ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, when `APP_SHOW_ONLY_ASSIGNED_CONVERSATIONS` is enabled, direct conversation view correctly blocks users who are neither the assignee nor the creator. The `s... πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24195 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts Β· 0 favs Β· 0 replies Β· Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
🚨 EUVD-2026-24197 πŸ“Š Score: 7.1/10 (CVSS v3.1) πŸ“¦ Product: freescout 🏒 Vendor: freescout-help-desk πŸ“… Updated: 2026-04-21 πŸ“ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, `MailboxesController::updateSave()` persists `chat_start_new` outside the allowed-field filter. A user with only the mailbox `sig` permission sees only the ... πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24197 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts Β· 0 favs Β· 0 replies Β· Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
🚨 EUVD-2026-24184 πŸ“Š Score: 7.6/10 (CVSS v3.1) πŸ“¦ Product: freescout 🏒 Vendor: freescout-help-desk πŸ“… Updated: 2026-04-21 πŸ“ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, a low-privileged agent can edit a visible customer and add an email address already owned by a hidden customer in another mailbox. The server discloses the ... πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24184 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts Β· 0 favs Β· 0 replies Β· Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
🚨 EUVD-2026-24185 πŸ“Š Score: 4.3/10 (CVSS v3.1) πŸ“¦ Product: freescout 🏒 Vendor: freescout-help-desk πŸ“… Updated: 2026-04-21 πŸ“ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the Change Customer modal exposes a β€œCreate a new customer” flow via POST /customers/ajax with action=create. Under limited visibility, the endpoint drops u... πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24185 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts Β· 0 favs Β· 0 replies Β· Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
🚨 EUVD-2026-24221 πŸ“Š Score: 7.1/10 (CVSS v3.1) πŸ“¦ Product: freescout 🏒 Vendor: freescout-help-desk πŸ“… Updated: 2026-04-21 πŸ“ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the reply and draft flows trust client-supplied encrypted attachment IDs. Any IDs present in `attachments_all[]` but omitted from retained lists are decrypt... πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24221 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts Β· 0 favs Β· 0 replies Β· Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
🚨 EUVD-2026-24223 πŸ“Š Score: 9.1/10 (CVSS v3.1) πŸ“¦ Product: freescout 🏒 Vendor: freescout-help-desk πŸ“… Updated: 2026-04-21 πŸ“ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, FreeScout's module installation feature extracts ZIP archives without validating file paths, allowing an authenticated admin to write files arbitrarily on t... πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24223 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts Β· 0 favs Β· 0 replies Β· Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
🚨 EUVD-2026-24225 πŸ“Š Score: 5.4/10 (CVSS v3.1) πŸ“¦ Product: freescout 🏒 Vendor: freescout-help-desk πŸ“… Updated: 2026-04-21 πŸ“ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the mailbox OAuth disconnect action is implemented as `GET /mailbox/oauth-disconnect/{id}/{in_out}/{provider}`. It removes stored OAuth metadata from the ma... πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24225 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts Β· 0 favs Β· 0 replies Β· Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability