FreeScout
cpe:2.3:a:freescout:freescout:*:*:*:*:*:*:*
- < 1.8.179
A vulnerability in FreeScout prior to version 1.8.179 allows users to manipulate notification settings for mailboxes, potentially gaining unauthorized access. The application fails to properly verify user permissions when disabling or enabling notifications, enabling an attacker to access information or functionality beyond their granted privileges. This issue has been addressed in version 1.8.179.
Exploitation of this vulnerability could lead to unauthorized access to mailboxes and their associated information or functionalities.
To reproduce this vulnerability, send a POST request to the '/mailbox/ajax' endpoint with the 'action' parameter set to 'mute', the 'mailbox_id' parameter indicating the target mailbox, and the 'mute' parameter set to '1'. If the user does not have access to the specified mailbox, this action will grant access, allowing the user to manipulate mailbox settings.
Users are advised to update to FreeScout version 1.8.179 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.