PT-2026-34031 · Freescout · Freescout
Published
2026-04-21
·
Updated
2026-04-21
·
CVE-2026-41191
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
FreeScout versions prior to 1.8.215
Description
The
MailboxesController::updateSave() function persists the chat start new variable outside the allowed-field filter. This allows a user who possesses only the mailbox sig permission to modify the hidden mailbox-wide chat setting through a direct POST request, despite the user interface only displaying the signature field.Recommendations
Update to version 1.8.215.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freescout