PT-2026-108190 · Freescout · Freescout
CVE-2026-107393
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FreeScout versions prior to 1.8.235
Description
When the
APP CLOUDFLARE IS USED setting is enabled, the software trusts an unvalidated CF-Connecting-IP header during failed login attempts and records the spoofed value in the activity log. The LogsMonitor then inserts this value into an administrator alert email without HTML escaping, which allows injected HTML to execute when an administrator opens the email.Recommendations
Update to version 1.8.235.
Fix
Improper Encoding or Escaping of Output
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freescout