CVE-2023-52268: Critical severity Freescout End-User Portal vulnerability
Published Nov 12, 2024
·Updated
The End-User Portal module before 1.0.65 for FreeScout sometimes allows an attacker to authenticate as an arbitrary user because a session token can be sent to the /auth endpoint. NOTE: this module is not part of freescout-helpdesk/freescout on GitHub.
Affected Software
1 affected component
Freescout End-User Portal<1.0.65
Event History
Nov 12, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-52268?
CVE-2023-52268 is considered a critical vulnerability due to its potential to allow unauthorized user authentication.
2
How do I fix CVE-2023-52268?
To fix CVE-2023-52268, upgrade the FreeScout End-User Portal module to version 1.0.65 or higher.
3
What impact does CVE-2023-52268 have on affected systems?
CVE-2023-52268 can lead to unauthorized access, allowing attackers to authenticate as any user.
4
Which versions of FreeScout End-User Portal are affected by CVE-2023-52268?
Versions of FreeScout End-User Portal before 1.0.65 are affected by CVE-2023-52268.
5
Is there a public exploit for CVE-2023-52268?
At this time, there is no known public exploit for CVE-2023-52268 reported.