CVE-2026-45295
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Summary
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tracking endpoint GET /thread/read/{conversation_id}/{thread_id} allows unauthenticated attackers to enumerate valid conversation and thread IDs, and modify thread state (opened_at timestamp) without any authentication. Version 1.8.219 patches the issue.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| freescout-help-desk | freescout | < 1.8.219 | affected |
Weaknesses
- CWE-639: CWE-639: Authorization Bypass Through User-Controlled Key
- CWE-862: CWE-862: Missing Authorization
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: yes
- Technical Impact: partial
Additional References
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.