FreeScout 是一款自托管的帮助台系统和共享邮箱。在版本 1.8.235 之前,当启用 配置时,FreeScout 在登录失败时信任未经验证的 请求头,并将伪造的值记录到活动日志中。LogsMonitor 模块将该值插入到管理员警报电子邮件中,但未进行 HTML 转义处理,导致管理员在打开该电子邮件时可能执行注入的 HTML 代码(例如通过 HTML 注入实现跨站脚本攻击 XSS)。此问题已在版本 1.8.235 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| freescout-help-desk | freescout | < 1.8.235 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet