FreeScout versions prior to 1.8.213 are vulnerable to Server-Side Request Forgery (SSRF) and arbitrary HTML injection in outgoing emails, which could allow attackers to exploit the system.
Claims
FreeScout versions prior to 1.8.213 are vulnerable to Server-Side Request Forgery (SSRF) and arbitrary HTML injection in outgoing emails, which could allow attackers to exploit the system.
Parent: Software SecurityEntity: FreeScoutImpact: negativeDate: Apr 21, 2026Target: FreeScout's security practices and software updates
Source posts
๐จ EUVD-2026-24167
๐ Score: 4.1/10 (CVSS v3.1)
๐ฆ Product: freescout
๐ข Vendor: freescout-help-desk
๐
Updated: 2026-04-21
๐ FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a Server-Side Request Forgery (SSRF) vulnerability in the IMAP/SMTP connection test functionality of FreeScout's `MailboxesController`. Three AJAX acti...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24167
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24168
๐ Score: 5.8/10 (CVSS v3.1)
๐ฆ Product: freescout
๐ข Vendor: freescout-help-desk
๐
Updated: 2026-04-21
๐ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, an unauthenticated attacker can inject arbitrary HTML into outgoing emails generated by FreeScout by sending an email with a crafted From display name. The ...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24168
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24187
๐ Score: 7.1/10 (CVSS v3.1)
๐ฆ Product: freescout
๐ข Vendor: freescout-help-desk
๐
Updated: 2026-04-21
๐ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the phone-conversation creation flow accepts attacker-controlled `customer_id`, `name`, `to_email`, and `phone` values and resolves the target customer in t...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24187
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24189
๐ Score: 5.9/10 (CVSS v3.1)
๐ฆ Product: freescout
๐ข Vendor: freescout-help-desk
๐
Updated: 2026-04-21
๐ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.214, the undo-send route `GET /conversation/undo-reply/{thread_id}` checks only whether the current user can view the parent conversation. It does not verify tha...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24189
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24191
๐ Score: 4.3/10 (CVSS v3.1)
๐ฆ Product: freescout
๐ข Vendor: freescout-help-desk
๐
Updated: 2026-04-21
๐ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, the assigned-only restriction is applied to direct conversation view and folder queries, but not to non-folder query builders. Global search and the AJAX fi...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24191
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24193
๐ Score: 7.1/10 (CVSS v3.1)
๐ฆ Product: freescout
๐ข Vendor: freescout-help-desk
๐
Updated: 2026-04-21
๐ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, customer-thread editing is authorized through `ThreadPolicy::edit()`, which checks mailbox access but does not apply the assigned-only restriction from `Con...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24193
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24195
๐ Score: 7.1/10 (CVSS v3.1)
๐ฆ Product: freescout
๐ข Vendor: freescout-help-desk
๐
Updated: 2026-04-21
๐ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, when `APP_SHOW_ONLY_ASSIGNED_CONVERSATIONS` is enabled, direct conversation view correctly blocks users who are neither the assignee nor the creator. The `s...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24195
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24197
๐ Score: 7.1/10 (CVSS v3.1)
๐ฆ Product: freescout
๐ข Vendor: freescout-help-desk
๐
Updated: 2026-04-21
๐ FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.215, `MailboxesController::updateSave()` persists `chat_start_new` outside the allowed-field filter. A user with only the mailbox `sig` permission sees only the ...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24197
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 21, 2026
#cybersecurity#infosec#euvd#cve#vulnerability