Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
FreeScout Allows Unauthenticated Access to Legacy Attachment Files
Vulnerability Description
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.221, FreeScout's attachment download route skips token authentication for any attachment whose `token_type` is set to `1` (`TOKEN_TYPE_LEGACY`). Because this route is unauthenticated and the file path is deterministic, an unauthenticated remote attacker can download any attachment that was created by an older version of FreeScout without possessing a valid token or session. Version 1.8.221 contains a fix.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
认证机制不恰当
Vulnerability Title
FreeScout 授权问题漏洞
Vulnerability Description
FreeScout是FreeScout公司开源的一个使用 PHP(Laravel 框架)构建的超轻量级且功能强大的免费开源帮助台和共享收件箱。 FreeScout 1.8.221之前版本存在授权问题漏洞,该漏洞源于附件下载路由跳过token_type设置为1的附件的令牌认证,由于此路由未经身份验证且文件路径是确定的,可能导致未经身份验证的远程攻击者下载由旧版本创建的任何附件。
CVSS Information
N/A
Vulnerability Type
N/A