CVE-2025-48471: FreeScout Vulnerable to Arbitrary File Upload
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, the application does not check or performs insufficient checking of files uploaded to the application. This allows files to be uploaded with the phtml and phar extensions, which can lead to remote code execution if the Apache web server is used. This issue has been patched in version 1.8.179.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48471?
CVE-2025-48471 has a medium severity level due to the potential for remote code execution through unsafe file uploads.
How do I fix CVE-2025-48471?
To fix CVE-2025-48471, upgrade to FreeScout version 1.8.179 or later where the vulnerability has been addressed.
What are the affected versions for CVE-2025-48471?
CVE-2025-48471 affects FreeScout versions prior to 1.8.179.
What type of files can be uploaded due to CVE-2025-48471?
CVE-2025-48471 allows the upload of files with phtml and phar extensions, which can be exploited for remote code execution.
Is CVE-2025-48471 a local or remote vulnerability?
CVE-2025-48471 is a remote vulnerability as it allows attackers to upload malicious files that can be executed remotely.