CVE-2025-48474: FreeScout Vulnerable to Insufficient Authorization
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application incorrectly checks user access rights for conversations. Users with showonlyassignedconversations enabled can assign themselves to an arbitrary conversation from the mailbox to which they have access, thereby bypassing the restriction on viewing conversations. This issue has been patched in version 1.8.180.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48474?
CVE-2025-48474 is considered a moderate severity vulnerability.
What are the consequences of CVE-2025-48474?
CVE-2025-48474 allows users to assign themselves to arbitrary conversations, potentially accessing sensitive data.
How do I fix CVE-2025-48474?
To mitigate CVE-2025-48474, upgrade FreeScout to version 1.8.180 or later.
Who is affected by CVE-2025-48474?
CVE-2025-48474 affects all versions of FreeScout prior to 1.8.180.
What is the nature of CVE-2025-48474?
CVE-2025-48474 involves improper access control in FreeScout regarding user rights for conversations.