FreeScout, a free self-hosted help desk and shared mailbox platform, contains an insecure direct object reference vulnerability in versions prior to 1.8.215. The flaw exists in the reply and draft flows, which improperly trust client-supplied encrypted attachment IDs, allowing authenticated attackers to delete attachments belonging to other mailbox users by replaying encrypted IDs through the save_draft function. The vulnerability affects the integrity and availability of shared mailbox data, as attackers can remove attachments from conversations visible to them. The vulnerability has a CVSS score of 7.1 (HIGH) with a network attack vector requiring low complexity and user authentication but no user interaction. The impact is high for integrity (via unauthorized attachment deletion) and moderate for availability, while confidentiality remains unaffected. The EPSS score of 0.00034 indicates minimal current threat landscape prevalence relative to other vulnerabilities. There is no evidence of active exploitation or public exploit code availability. The vulnerability is not listed in the CISA KEV catalog and has an inactive status on the hot list, suggesting limited community attention and low current exploitation risk. Organizations using FreeScout should prioritize upgrading to version 1.8.215 or later to remediate this privilege escalation and data destruction risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Freescout-Help-Desk | Freescout | < 1.8.215CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.