Medium severity6.5NVD Advisory· Published Jul 20, 2026· Updated Jul 21, 2026
CVE-2026-45295
CVE-2026-45295
Description
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tracking endpoint GET /thread/read/{conversation_id}/{thread_id} allows unauthenticated attackers to enumerate valid conversation and thread IDs, and modify thread state (opened_at timestamp) without any authentication. Version 1.8.219 patches the issue.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.