PT-2026-34030 · Freescout · Freescout
Published
2026-04-21
·
Updated
2026-04-21
·
CVE-2026-41190
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
FreeScout versions prior to 1.8.215
Description
When the
APP SHOW ONLY ASSIGNED CONVERSATIONS setting is enabled, the system correctly restricts access to conversation views for users who are not the creator or the assignee. However, the 'save draft' AJAX path lacks sufficient validation, allowing a direct POST request to create a draft within a conversation that should be hidden in the user interface.Recommendations
Update to version 1.8.215.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freescout