Back to database
Soon61Medium6.1VulnerabilityCVE-2026-107393No patch link observed

CVE-2026-107393 — FreeScout is a self-hosted help desk and shared mailbox.

Published Oct 8, 2026, 08:17 PM UTCIngested 1h agoSource NVD(cve-db)CVE-2026-107393

Description

FreeScout is a self-hosted help desk and shared mailbox. Prior to 1.8.235, when APP_CLOUDFLARE_IS_USED is enabled, FreeScout trusts an unvalidated CF-Connecting-IP header during failed login attempts and stores the spoofed value in the activity log. LogsMonitor inserts the value into an administrator alert email without HTML escaping, allowing injected HTML to execute when an administrator opens the email. This issue is fixed in version 1.8.235.

CVSS v3.1 base metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
6.1

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

Low

Attack Complexity

PR

None

Privileges Required

UI

Required

User Interaction

S

Changed

Scope

C

Low

Confidentiality

I

Low

Integrity

A

None

Availability