PT-2024-26114 · Freescout · Freescout

Umeradeemcheema

·

Published

2024-05-13

·

Updated

2025-01-10

·

CVE-2024-34697

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions FreeScout versions prior to 1.8.139
Description A stored HTML Injection issue has been identified in the Email Receival Module of the FreeScout Application. This issue allows attackers to inject malicious HTML content into emails sent to the application's mailbox due to improper handling of HTML content within incoming emails. Attackers can embed malicious HTML code in the context of the application's domain, potentially leading to attacks such as form hijacking, application defacement, or data exfiltration via CSS injection. Unauthenticated attackers can exploit this issue, although they are limited to HTML injection, the consequences can still be severe.
Recommendations For versions prior to 1.8.139, update to version 1.8.139, which implements strict input validation and sanitization mechanisms to prevent malicious HTML injections.

Exploit

Fix

Special Elements Injection

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-34697
GHSA-985R-6QFC-HG8M

Affected Products

Freescout