Cross-Site Scripting in FreeScout Help Desk by FreeScout
CVE-2026-107393
6.1MEDIUM
What is CVE-2026-107393?
FreeScout, a self-hosted help desk platform, was vulnerable to a Cross-Site Scripting (XSS) attack due to improper validation of the CF-Connecting-IP header when the APP_CLOUDFLARE_IS_USED setting is enabled. During failed login attempts, the application accepted and logged a spoofed IP address, which could then be included in administrator alert emails without proper HTML escaping. This flaw allowed attackers to execute arbitrary HTML or script code when an administrator viewed the email. The vulnerability was addressed in version 1.8.235.
Affected Version(s)
freescout < 1.8.235
