Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-29184

Опубликовано: 22 мар. 2024
Источник: nvd
CVSS3: 8
EPSS Низкий

Описание

FreeScout is a self-hosted help desk and shared mailbox. A Stored Cross-Site Scripting (XSS) vulnerability has been identified within the Signature Input Field of the FreeScout Application prior to version 1.8.128. Stored XSS occurs when user input is not properly sanitized and is stored on the server, allowing an attacker to inject malicious scripts that will be executed when other users access the affected page. In this case, the Support Agent User can inject malicious scripts into their signature, which will then be executed when viewed by the Administrator.

The application protects users against XSS attacks by enforcing a CSP policy, the CSP Policy is: script-src 'self' 'nonce-abcd' . The CSP policy only allows the inclusion of JS files that are present on the application server and doesn't allow any inline script or script other than nonce-abcd. The CSP policy was bypassed by uploading a JS file to the server by a POST request to /conversation/upload endpoint. After this, a w

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:freescout:freescout:*:*:*:*:*:*:*:*
Версия до 1.8.128 (исключая)

EPSS

Процентиль: 62%
0.00434
Низкий

8 High

CVSS3

Дефекты

CWE-79
CWE-79

EPSS

Процентиль: 62%
0.00434
Низкий

8 High

CVSS3

Дефекты

CWE-79
CWE-79