FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylist that neutralizes dangerous file uploads (Helper::$restricted_extensions) is incomplete: it does not cover the .pht extension. The authenticated upload endpoint POST /uploads/upload (SecureController@upload) stores files with their original extension into the web-accessible directory storage/app/public/uploads/ (served at /storage/uploads/). On the standard Apache + libapache2-mod-php deployment, the default handler <FilesMatch ".+\.ph(ar|p[3457]?|t|tml)$"> executes .pht, so any authenticated agent can upload a .pht web shell and run arbitrary commands as the web-server user (www-data). This is a direct bypass of the fix for CVE-2025-48471, which added phtml/phar but not pht (nor phtm, phps). Version 1.8.224 contains an updated fix.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone exploit containing one Bash script (exploit.sh) and a README. It is not part of a larger exploitation framework. The script operationalizes a two-stage exploit chain against FreeScout <= 1.8.223: first, it abuses CVE-2026-53595 to perform anonymous account takeover by requesting and posting to /user-setup/%20/<current_unix_timestamp>, extracting a CSRF token from the setup form, and overwriting the targeted account's email and password. The logic relies on the documented behavior that an activated user's invite_hash is empty, that MySQL/MariaDB VARCHAR comparison ignores trailing spaces so %20 matches '', and that the invite_sent_at validation accepts a plaintext timestamp when decryption fails. After takeover, the script uses the authenticated upload endpoint /uploads/upload to exploit CVE-2026-53593 by uploading a temporary .pht file containing a minimal PHP webshell (system($_GET["c"])). It parses the JSON response with jq to recover the uploaded file URL, then either executes a single attacker-supplied command through the webshell or sends a base64-encoded Bash reverse shell one-liner to avoid quoting and /bin/sh compatibility issues. The expected result is command execution as the web server user, typically www-data. Repository structure is minimal and purpose-built: README.md documents the vulnerability chain, affected versions, usage examples, requirements, and remediation; exploit.sh contains all exploit logic, argument parsing, CSRF extraction, takeover requests, upload handling, and payload delivery. This is a real exploit rather than a detector, with hardcoded but user-adjustable credentials and callback parameters, making it an operational PoC rather than a framework-grade weaponized module.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.