Vulnerabilities in freescout-helpdesk
6 resultsVexday analysis
FreeScout acumula 6 vulnerabilidades catalogadas, com 1 classificada como crítica, mas nenhuma sob exploração ativa conhecida. O risco permanece contido, não há divulgações recentes, embora a fraqueza dominante (CWE-1321 - Improperly Controlled Modification of Object Attribute Properties in Python Class) sinalize potencial de escalação em futuras versões.
CVE-2024-29185CRITICALFreeScout OS Command Injection vulnerabilityEPSS 1.7%CVE-2024-29184HIGHFreeScout Stored XSS to Privilege Escalation After CSP BypassEPSS 0.9%CVE-2024-34697HIGHFreescout vulnerable to Stored HTML Injection in Editing Received EmailsEPSS 0.6%CVE-2024-28186HIGHSMTP Mail Credentials Disclosed in Error Log in freescoutEPSS 0.6%CVE-2024-34698MEDIUMPrototype Pollution in getQueryParam Function (URL Query Parser)EPSS 0.5%CVE-2024-1932MEDIUMUnrestricted Upload of File with Dangerous Type in freescout-helpdesk/freescoutEPSS 0.4%