SVG Injection Vulnerability in FreeScout Help Desk by FreeScout
CVE-2026-32753
8.5HIGH
What is CVE-2026-32753?
FreeScout, a PHP-based help desk solution, has a vulnerability in versions 1.8.208 and below that allows attackers to upload and render malicious SVG files. By exploiting the improper checking of file extensions and Content-Types, attackers can use a file with a deceptive name like 'xss.png' while setting the Content-Type to 'image/svg+xml'. This circumvention allows them to execute JavaScript within the SVG, leading to potential Cross-Site Scripting (XSS) attacks. Authenticated users can trigger these scripts, allowing unauthorized actions on behalf of other users. This issue was addressed in version 1.8.209.
Affected Version(s)
freescout < 1.8.209
