Ad

CVE-2026-34442

MEDIUM CVSS 3.1: 6.1 EPSS 0.08%
Updated Apr 01, 2026
PHP
Parameter Value
CVSS 6.1 (MEDIUM)
Affected Versions before 1.8.211
Fixed In 1.8.211
Type CWE-601 (Open Redirect), CWE-20 (Improper Input Validation), CWE-829 (Inclusion of Functionality from Untrusted Source)
Vendor PHP
Public PoC No

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.211, host header manipulation in FreeScout version (http://localhost:8080/system/status) allows an attacker to inject an arbitrary domain into generated absolute URLs. This leads to External Resource Loading and Open Redirect behavior.

When the application constructs links and assets using the unvalidated Host header, user requests can be redirected to attacker-controlled domains and external resources may be loaded from malicious servers. This issue has been patched in version 1.8.211.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Freescout Freescout
cpe:2.3:a:freescout:freescout:*:*:*:*:*:*:*:*
1.8.211