PT-2026-33912 · Freescout · Freescout

Published

2026-04-21

·

Updated

2026-04-21

·

CVE-2026-40497

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions FreeScout versions prior to 1.8.213
Description The Helper::stripDangerousTags() function fails to remove <style> tags, although it strips <script>, <form>, <iframe>, and <object> tags. The mailbox signature field, saved via the endpoint '/mailbox/settings/{id}', is rendered unescaped in conversation views. Because the Content Security Policy allows style-src * 'self' 'unsafe-inline', an attacker with access to mailbox settings, such as an admin or an agent with mailbox permissions, can inject CSS attribute selectors. This allows the exfiltration of the CSRF token of any agent or admin viewing a conversation in that mailbox. With this token, the attacker can perform state-changing actions, such as creating admin accounts or changing email and password details, leading to privilege escalation from agent to admin.
Recommendations Update to version 1.8.213.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40497

Affected Products

Freescout