Vulnerabilità ed exploit · Exploit zero-day

FreeScout: RCE Zero-Click Permette Compromissione Completa del Server

FreeScout contiene una vulnerabilità critica (CVE-2026-28289) che permette RCE senza autenticazione e senza interazione dell'utente. La falla bypassa la correzione per CVE-2026-27636 usando un zero-width space (U+200B) che genera un TOCTOU nella sanitizzazione dei nomi file e consente di salvare un .htaccess dotfile. Un allegato email maligno può essere scritto sotto /storage/attachment e richiamato via web per eseguire comandi sul server.

4 fonti · 5 mar

CVE-2026-28289

NVD KEV

CVSS 10 CRITICAL: freeScout is a free help desk and shared inbox built with PHP's Laravel framework. EPSS 3% (84º percentile).

CVE-2026-27636

NVD KEV

CVSS 8.8 HIGH: freeScout is a free help desk and shared inbox built with PHP's Laravel framework. EPSS 2% (81º percentile).

Cronologia

Fonti

Part of the PlainSec briefing for 2026-03-05

Every edition of this story: FreeScout: RCE Zero-Click Permette Compromissione Completa del Server

Altro da oggi