Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-32753

Опубликовано: 19 мар. 2026
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. In versions 1.8.208 and below, bypasses of the attachment view logic and SVG sanitizer make it possible to upload and render an SVG that runs malicious JavaScript. An extension of .png with content type of image/svg+xml is allowed, and a fallback mechanism on invalid XML leads to unsafe sanitization. The application restricts which uploaded files are rendered inline: only files considered "safe" are displayed in the browser; others are served with Content-Disposition: attachment. This decision is based on two checks: the file extension (e.g. .png is allowed, while .svg may not be) and the declared Content-Type (e.g. image/* is allowed). By using a filename with an allowed extension (e.g. xss.png) and a Content-Type of image/svg+xml, an attacker can satisfy both checks and cause the server to treat the upload as a safe image and render it inline, even though the body is SVG and can contain scripted behavi

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:freescout:freescout:*:*:*:*:*:*:*:*
Версия до 1.8.209 (исключая)

EPSS

Процентиль: 11%
0.00207
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-80

Связанные уязвимости

CVSS3: 7.3
fstec
5 месяцев назад

Уязвимость системы управления службой поддержки FreeScout, связанная с непринятием мер по нейтрализации script-related тэгов HTML на веб-странице, позволяющая нарушителю провести атаку межсайтового скриптинга (XSS)

EPSS

Процентиль: 11%
0.00207
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-80