Impact
FreeScout is a Laravel‑based help desk that allows users to upload arbitrary files. Prior to version 1.8.224 the upload endpoint lacks any rate limiting, enabling an attacker to flood the server with requests. This overloads the database layer, exhausting resources and leading to denial of service for all users. The flaw is a classic resource exhaustion vulnerability and is mapped to CWE‑400 and CWE‑770.
Affected Systems
The vulnerability affects the FreeScout help‑desk application developed by freescout‑help‑desk. Versions prior to 1.8.224 are impacted; the issue is fixed in version 1.8.224.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. The EPSS score of < 1% indicates a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers require no authentication. They can issue a large volume of upload requests to trigger database overload, causing service disruption.
OpenCVE Enrichment