โ† All reports

FreeScout versions prior to 1.8.213 are vulnerable to Server-Side Request Forgery (SSRF) and arbitrary HTML injection in outgoing emails, which could allow attackers to exploit the system.

CybersecurityTechnologyConflictApr 21, 2026score 0.172 posts ยท 0 replies across 1 instances
The thread discusses two vulnerabilities in the FreeScout help desk software, both related to security issues that could allow attackers to exploit the system. These vulnerabilities highlight the importance of software security updates and the risks associated with unpatched systems.

Claims

FreeScout versions prior to 1.8.213 are vulnerable to Server-Side Request Forgery (SSRF) and arbitrary HTML injection in outgoing emails, which could allow attackers to exploit the system.
Parent: Software SecurityEntity: FreeScoutImpact: negativeDate: Apr 21, 2026Target: FreeScout's security practices and software updates

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-24167 ๐Ÿ“Š Score: 4.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: freescout ๐Ÿข Vendor: freescout-help-desk ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a Server-Side Request Forgery (SSRF) vulnerability in the IMAP/SMTP connection test functionality of FreeScout's `MailboxesController`. Three AJAX acti... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24167 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24168 ๐Ÿ“Š Score: 5.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: freescout ๐Ÿข Vendor: freescout-help-desk ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can inject arbitrary HTML into outgoing emails generated by FreeScout by sending an email with a crafted From display name. The ... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24168 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24187 ๐Ÿ“Š Score: 7.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: freescout ๐Ÿข Vendor: freescout-help-desk ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the phone-conversation creation flow accepts attacker-controlled `customer_id`, `name`, `to_email`, and `phone` values and resolves the target customer in t... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24187 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24189 ๐Ÿ“Š Score: 5.9/10 (CVSS v3.1) ๐Ÿ“ฆ Product: freescout ๐Ÿข Vendor: freescout-help-desk ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route `GET /conversation/undo-reply/{thread_id}` checks only whether the current user can view the parent conversation. It does not verify tha... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24189 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24191 ๐Ÿ“Š Score: 4.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: freescout ๐Ÿข Vendor: freescout-help-desk ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the assigned-only restriction is applied to direct conversation view and folder queries, but not to non-folder query builders. Global search and the AJAX fi... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24191 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24193 ๐Ÿ“Š Score: 7.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: freescout ๐Ÿข Vendor: freescout-help-desk ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, customer-thread editing is authorized through `ThreadPolicy::edit()`, which checks mailbox access but does not apply the assigned-only restriction from `Con... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24193 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24195 ๐Ÿ“Š Score: 7.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: freescout ๐Ÿข Vendor: freescout-help-desk ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, when `APP_SHOW_ONLY_ASSIGNED_CONVERSATIONS` is enabled, direct conversation view correctly blocks users who are neither the assignee nor the creator. The `s... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24195 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24197 ๐Ÿ“Š Score: 7.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: freescout ๐Ÿข Vendor: freescout-help-desk ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, `MailboxesController::updateSave()` persists `chat_start_new` outside the allowed-field filter. A user with only the mailbox `sig` permission sees only the ... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24197 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability