PT-2026-30895 · Freescout Help Desk · Freescout
Published
2026-04-07
·
Updated
2026-04-07
·
CVE-2026-35584
CVSS v4.0
6.9
Medium
| AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.212, the endpoint GET /thread/read/{conversation id}/{thread id} does not require authentication and does not validate whether the given thread id belongs to the given conversation id. This allows any unauthenticated attacker to mark any thread as read by passing arbitrary IDs, enumerate valid thread IDs via HTTP response codes (200 vs 404), and manipulate opened at timestamps across conversations (IDOR). This vulnerability is fixed in 1.8.212.
Fix
Missing Authentication
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freescout