CRITICAL
The End-User Portal module before 1.0.65 for FreeScout sometimes allows an attacker to authenticate as an arbitrary user because a session token can be sent to the /auth endpoint
Published Nov 12, 2024
9.1
CRITICALCVSS 3.1
EPSS 0.62%
Description
Affected products
Remediation
References (4)
Change history (0)
No recorded changes yet.