CVE-2026-40497 - FreeScout Vulnerable to CSS Injection via Stored Style Tag in Mailbox Signature (CSRF Token Exfiltration)

CVE ID :CVE-2026-40497
Published : April 21, 2026, 3:16 a.m. | 1 hour, 6 minutes ago
Description :FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, FreeScout's `Helper::stripDangerousTags()` removes `

Comments

Popular posts from this blog

CVE-2026-17434 - nanocoai NanoClaw add_mcp_server request.ts handleAddMcpServer improper authorization