Vulnerabilidades em freescout-help-desk

73 resultados
Análise Vexday

O ecossistema de vulnerabilidades do FreeScout Help Desk acumula 65 CVEs catalogadas, com crescimento expressivo no volume recente — 33 entradas surgiram nos últimos 90 dias, o que indica atenção crescente da comunidade de pesquisa sobre a plataforma. A falha mais prevalente é do tipo CWE-79 (Cross-Site Scripting), padrão consistente com aplicações web de gestão de tickets e que, em ambientes corporativos, pode facilitar sequestro de sessão e movimentação lateral. Nenhuma CVE está atualmente no catálogo KEV da CISA, situando o produto abaixo da média geral de exploração ativa, embora CVE-2026-28289 mereça acompanhamento prioritário dado seu EPSS de 0,3114 — o mais alto do conjunto — e a existência de PoC pública circulando. As 6 CVEs de severidade crítica reforçam a necessidade de ciclos de patching disciplinados, especialmente diante da velocidade com que novas entradas têm sido registradas.

CVE-2025-48484MEDIUMFreeScout Vulnerable to Stored XSSEPSS 0.3%CVE-2025-48486MEDIUMFreeScout Vulnerable to Stored XSSEPSS 0.3%CVE-2025-48485MEDIUMFreeScout Vulnerable to Stored XSSEPSS 0.3%CVE-2026-40570MEDIUMFreeScout's Missing Authorization in load_customer_info Allows Any Authenticated User to Access Full Customer PIIEPSS 0.2%CVE-2026-41902CRITICALFreeScout's user invitation hash never expires: permanent unauthenticated account takeover if invite link leaksEPSS 0.2%CVE-2025-48875MEDIUMFreeScout Vulnerable to Stored XSSEPSS 0.2%CVE-2026-40497HIGHFreeScout Vulnerable to CSS Injection via Stored Style Tag in Mailbox Signature (CSRF Token Exfiltration)EPSS 0.2%CVE-2026-40567MEDIUMFreeScout has HTML Injection in Outgoing Emails via Unsanitized Customer Name in Signature VariablesEPSS 0.2%CVE-2026-40568HIGHFreeScout Vulnerable to XSS via Mailbox Signature Due to Incomplete HTML SanitizationEPSS 0.2%CVE-2026-40592MEDIUMFreeScout's cross-user undo reply allows mailbox peers to recall another agent's outbound replyEPSS 0.2%CVE-2026-41192HIGHFreeScout's client-controlled attachment IDs allow deletion of existing conversation attachmentsEPSS 0.2%CVE-2026-40589HIGHFreeScout has Customer Edit Cross-Mailbox Email TakeoverEPSS 0.2%CVE-2026-39384HIGHFreeScout Customer Merge Cross-Mailbox Authorization BypassEPSS 0.2%CVE-2026-41183MEDIUMFreeScout allows non-folder conversation queries to disclose assigned-only hidden conversationsEPSS 0.2%CVE-2026-41189HIGHFreeScout has assigned-only visibility bypass that allows editing hidden customer-authored threadsEPSS 0.2%CVE-2025-48489MEDIUMFreeScout Vulnerable to Stored XSSEPSS 0.2%CVE-2026-34442MEDIUMFreeScout: Host Header Injection Leading to External Resource Loading and Open Redirect in FreeScoutEPSS 0.2%CVE-2026-40590MEDIUMFreeScout's Customer AJAX Create Modifies Hidden Existing CustomerEPSS 0.2%CVE-2026-41190HIGHFreeScout has assigned-only visibility bypass via save_draft that allows hidden conversation draft injectionEPSS 0.2%CVE-2026-41191HIGHFreeScout's signature only mailbox permission allows unauthorized mailbox chat setting changesEPSS 0.2%