This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: FreeScout < 1.8.213 suffers from **Mass Assignment** in email connection settings.โฆ
๐ก๏ธ **CWE-284**: Improper Control of Generation of Code ('Code Injection') / Mass Assignment. ๐ฅ **Flaw**: `connectionIncomingSave` & `connectionOutgoingSave` pass `$request->all()` directly to `$mailbox->fill`.โฆ
๐ข **Vendor**: FreeScout (Laravel PHP Help Desk). ๐ฆ **Affected**: Versions **before 1.8.213**. โ **Safe**: 1.8.213 and later. ๐ **Published**: 2026-04-21.
Q4What can hackers do? (Privileges/Data)
๐ต๏ธ **Privileges**: Requires **Authenticated Admin** access. ๐ฏ **Impact**: Can modify **any fillable field** in the Mailbox model. ๐ฌ **Specifics**: Inject BCC addresses or hijack SMTP outgoing connections. ๐
Q5Is exploitation threshold high? (Auth/Config)
๐ **Threshold**: **High** for Auth, **Low** for Execution. ๐ **PR:H**: Requires High Privileges (Admin). โก **AC:L**: Low Complexity. ๐ฑ๏ธ **UI:N**: No User Interaction needed once logged in. ๐ **CVSS**: High (8.1+).
Q6Is there a public Exp? (PoC/Wild Exploitation)
๐ซ **Public Exp**: **No** public PoC or wild exploitation detected yet. ๐ **Status**: POCs list is empty in data. ๐ **Reference**: GHSA advisory confirms vulnerability but no exploit code shared. ๐ต๏ธโโ๏ธ
Q7How to self-check? (Features/Scanning)
๐ **Check**: Scan for FreeScout instances. ๐ **Verify**: Check version number in footer/config. ๐ ๏ธ **Feature**: Look for 'Connection Settings' endpoints.โฆ
โ **Fixed**: Yes! Patched in **v1.8.213**. ๐ **Commit**: `f45b9105d43b0352c08fcca154e8ae6177c3d860`. ๐ฅ **Action**: Upgrade immediately via GitHub releases. ๐
Q9What if no patch? (Workaround)
๐ก๏ธ **Workaround**: If stuck on old version, **restrict Admin access** strictly. ๐ซ **Mitigation**: Implement WAF rules to block mass-assignment payloads on `/connection/save` endpoints.โฆ