PT-2026-61703 · Freescout · Freescout

CVE-2026-53593

·

Published

2026-07-20

·

Updated

2026-07-21

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeScout versions prior to 1.8.224
Description An incomplete denylist in the Helper::$restricted extensions variable fails to block the .pht file extension. This allows an authenticated agent to upload a web shell via the POST /uploads/upload endpoint (SecureController@upload), which stores files in the web-accessible directory storage/app/public/uploads/. In standard Apache deployments using libapache2-mod-php, the server executes .pht files, enabling the attacker to run arbitrary commands as the web-server user (www-data).
Recommendations Update to version 1.8.224.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-53593
GHSA-27VP-FPG8-J8WV

Affected Products

Freescout