Cross-Site Scripting in FreeScout Help Desk by FreeScout
CVE-2026-107393

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107393?

FreeScout, a self-hosted help desk platform, was vulnerable to a Cross-Site Scripting (XSS) attack due to improper validation of the CF-Connecting-IP header when the APP_CLOUDFLARE_IS_USED setting is enabled. During failed login attempts, the application accepted and logged a spoofed IP address, which could then be included in administrator alert emails without proper HTML escaping. This flaw allowed attackers to execute arbitrary HTML or script code when an administrator viewed the email. The vulnerability was addressed in version 1.8.235.

Affected Version(s)

freescout < 1.8.235

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.