top of page
perceptive_background_267k.jpg

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, FreeScout does not take the limit_user_customer_visibility …

Published:

6 april 2026 om 22:00:00

Alert date:

7 april 2026 om 18:06:01

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

FreeScout, a free help desk and shared inbox application built with PHP's Laravel framework, contains a vulnerability prior to version 1.8.212. The application fails to properly enforce the limit_user_customer_visibility parameter when merging customers, potentially allowing unauthorized access to customer information. This access control bypass could lead to information disclosure where users can view customer data they should not have access to. The vulnerability has been addressed in FreeScout version 1.8.212 with proper enforcement of user visibility limits during customer merge operations.

Technical details

Mitigation steps:

Affected products:

FreeScout

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page