PT-2026-61703 · Freescout Help Desk · Freescout
CVE-2026-53593
·
Published
2026-07-20
·
Updated
2026-07-20
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylist that neutralizes dangerous file uploads (
Helper::$restricted extensions) is incomplete: it does not cover the .pht extension. The authenticated upload endpoint POST /uploads/upload (SecureController@upload) stores files with their original extension into the web-accessible directory storage/app/public/uploads/ (served at /storage/uploads/). On the standard Apache + libapache2-mod-php deployment, the default handler <FilesMatch ".+.ph(ar|p[3457]?|t|tml)$"> executes .pht, so any authenticated agent can upload a .pht web shell and run arbitrary commands as the web-server user (www-data). This is a direct bypass of the fix for CVE-2025-48471, which added phtml/phar but not pht (nor phtm, phps). Version 1.8.224 contains an updated fix.Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freescout