Descripción
FreeScout is a free help desk and shared inbox built with PHP-s Laravel framework. Prior to 1.8.220, the email processing pipeline in FreeScout-s FetchEmails command has two code paths for identifying agent (user) replies based on In-Reply-To / References headers. The notification reply path (notify-{thread_id}-{user_id}-...) extracts thread_id and user_id directly from the Message-ID without HMAC verification. An external attacker who can spoof the From address of a helpdesk agent can inject messages that FreeScout processes as legitimate agent replies — which are then automatically forwarded to customers via the legitimate SMTP server. This vulnerability is fixed in 1.8.220.
CVSS 7.5EPSS 0.145%Riesgo 0.76
Ver fuente- Publicación
- 2026-05-29 20:16:28
- Versiones afectadas
- <1.8.220
- Tipo
- Installed app
- Última modificación
- 2026-07-22 06:10:00
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N