Impact
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. An unauthenticated attacker can inject a message into any existing support conversation by sending a single email to the help desk's public address with a crafted In‑Reply‑To header. No credentials, tokens or prior access are required. The injected message appears as a legitimate customer reply in the agent UI, automatically reopens the conversation, and updates the last_reply_from field to the attacker’s identity. This vulnerability enables attackers to modify agent visibility and conversation history without authentication, constituting an authentication bypass (CWE‑287).
Affected Systems
The vulnerability affects all installations of FreeScout prior to version 1.8.223. Systems running the freescout product from the freescout‑help‑desk vendor are susceptible until a patch is applied.
Risk and Exploitability
The issue has a CVSS score of 8.6, indicating high severity. The EPSS score is 0.00215 (<1%), and the vulnerability is not listed in the CISA KEV catalog. Because the attack vector relies only on sending a crafted email to the public address, no authentication or additional privileges are required. An attacker can add deceptive or malicious content to any conversation, potentially misleading agents or manipulating ticket status.
OpenCVE Enrichment