← Retour aux CVEs
CVE-2026-34442
MEDIUM5.4
Description
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header manipulation in FreeScout version (http://localhost:8080/system/status) allows an attacker to inject an arbitrary domain into generated absolute URLs. This leads to External Resource Loading and Open Redirect behavior. When the application constructs links and assets using the unvalidated Host header, user requests can be redirected to attacker-controlled domains and external resources may be loaded from malicious servers. This issue has been patched in version 1.8.211.
Details CVE
Score CVSS v3.15.4
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurREQUIRED
Publie3/31/2026
Derniere modification4/1/2026
Sourcenvd
Observations honeypot0
Produits affectes
freescout:freescout
Faiblesses (CWE)
CWE-20CWE-601CWE-829CWE-601
References
https://github.com/freescout-help-desk/freescout/commit/889d75c8e3c15e6a7ddb6a4d4f65cc0379c29213(security-advisories@github.com)
https://github.com/freescout-help-desk/freescout/releases/tag/1.8.211(security-advisories@github.com)
https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-822g-7rw5-53xj(security-advisories@github.com)
https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-822g-7rw5-53xj(134c704f-9b21-4f2e-91b3-4a467353bcc0)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.