top of page
perceptive_background_267k.jpg

FreeScout is a free self-hosted help desk and shared mailbox. Versions prior to 1.8.213 have a stored cross-site scripting (XSS) vulnerability in the mailbox si…

Published:

20 april 2026 om 22:00:00

Alert date:

21 april 2026 om 18:10:28

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

FreeScout versions prior to 1.8.213 contain a stored cross-site scripting vulnerability in the mailbox signature feature. The vulnerability stems from incomplete HTML sanitization that only blocks four HTML tags but allows dangerous event handler attributes. Authenticated users with signature permissions can inject arbitrary HTML and JavaScript that executes automatically when agents or administrators view conversations. This enables session hijacking, phishing attacks, email exfiltration, and self-propagating worm behavior across mailboxes. The issue is fixed in version 1.8.213.

Technical details

Mitigation steps:

Affected products:

FreeScout

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page