Vulnerabilidades em freescout-help-desk

73 resultados
Análise Vexday

O ecossistema de vulnerabilidades do FreeScout Help Desk acumula 65 CVEs catalogadas, com crescimento expressivo no volume recente — 33 entradas surgiram nos últimos 90 dias, o que indica atenção crescente da comunidade de pesquisa sobre a plataforma. A falha mais prevalente é do tipo CWE-79 (Cross-Site Scripting), padrão consistente com aplicações web de gestão de tickets e que, em ambientes corporativos, pode facilitar sequestro de sessão e movimentação lateral. Nenhuma CVE está atualmente no catálogo KEV da CISA, situando o produto abaixo da média geral de exploração ativa, embora CVE-2026-28289 mereça acompanhamento prioritário dado seu EPSS de 0,3114 — o mais alto do conjunto — e a existência de PoC pública circulando. As 6 CVEs de severidade crítica reforçam a necessidade de ciclos de patching disciplinados, especialmente diante da velocidade com que novas entradas têm sido registradas.

CVE-2026-53596MEDIUMFreeScout has unrestricted file upload without rate limiting that leads to resource exhaustion (DoS)EPSS 0.4%CVE-2025-48472MEDIUMFreeScout Vulnerable to Insufficient AuthorizationEPSS 0.4%CVE-2025-48475MEDIUMFreeScout Vulnerable to Insufficient AuthorizationEPSS 0.4%CVE-2025-48880MEDIUMFreeScout has Race Condition When Deleting UsersEPSS 0.4%CVE-2026-41193CRITICALFreeScout has Zip Slip path traversal in module installation that allows arbitrary file write leading to RCEEPSS 0.4%CVE-2025-48388HIGHFreeScout Has Insufficient Protection Against CRLF-injectionEPSS 0.4%CVE-2026-53591HIGHFreeScout Vulnerable to Unauthenticated Conversation Thread Injection via HMAC Length Bypass in FetchEmailsEPSS 0.4%CVE-2025-48473MEDIUMFreeScout Vulnerable to Insufficient AuthorizationEPSS 0.4%CVE-2026-45295MEDIUMFreeScout Vulnerable to Unauthenticated Thread Read-Status Manipulation and Conversation Enumeration via Open Tracking EndpointEPSS 0.3%CVE-2025-48482MEDIUMFreeScout Has Business Logic ErrorsEPSS 0.3%CVE-2025-48480HIGHFreeScout Has Business Logic ErrorsEPSS 0.3%CVE-2025-48479HIGHFreeScout Has Business Logic ErrorsEPSS 0.3%CVE-2026-35584MEDIUMFreeScout has an Unauthenticated IDOR in Open Tracking Endpoint Allows Cross-Conversation Thread Manipulation and EnumerationEPSS 0.3%CVE-2026-40569CRITICALFreeScout's Mass Assignment in Mailbox Connection Settings Enables Silent Email ExfiltrationEPSS 0.3%CVE-2026-40566MEDIUMFreeScout vulnerable to SSRF via IMAP/SMTP Connection Test EndpointsEPSS 0.3%CVE-2026-32752NONEFreeScout: Broken Access Control in ThreadPolicy — Any User Can Read/Edit All Customer MessagesEPSS 0.3%CVE-2026-34443MEDIUMFreeScout: SSRF protection bypass via broken CIDR check in checkIpByMask()EPSS 0.3%CVE-2026-41903MEDIUMFreeScout IDOR Vulnerability: PERM_EDIT_USERS allows modifying any user's notification subscriptions (incomplete fix of CVE-2025-48472)EPSS 0.3%CVE-2025-48487MEDIUMFreeScout Vulnerable to Stored XSSEPSS 0.3%CVE-2025-48488MEDIUMFreeScout Vulnerable to Stored XSSEPSS 0.3%