🟠 《高危安全漏洞:CVE-2026-53591》

CVSS 评分: 高危(8.6)  状态: Received  发布时间: 2026-07-20


漏洞描述

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthenticated attacker can inject messages into any existing support conversation by sending a single email to the helpdesk's public address with a crafted In-Reply-To header. No credentials, tokens, or prior access are required. The injected message is rendered in the agent UI as a legitimate customer reply, the conversation is automatically reopened, and the last_reply_from field is set to the attacker's identity. Version 1.8.223 contains a fix.


🔍 技术细节

字段
CVE ID CVE-2026-53591
CVSS 评分 8.6 🟠
严重程度 高危
CVSS 向量 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
CWE 分类 CWE-287
发布时间 2026-07-20
最后更新 2026-07-20
状态 Received
数据来源 security-advisories@github.com

🔗 参考链接