CVE-2025-48478: FreeScout Has Business Logic Errors
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, insufficient input validation during user creation has resulted in a mass assignment vulnerability, allowing an attacker to manipulate all fields of the object, which are enumerated in the $fillable array (the User object), when creating a new user. This issue has been patched in version 1.8.180.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48478?
CVE-2025-48478 has a medium severity level due to the mass assignment vulnerability it introduces.
How do I fix CVE-2025-48478?
To fix CVE-2025-48478, upgrade FreeScout to version 1.8.180 or later.
What are the consequences of CVE-2025-48478?
CVE-2025-48478 allows attackers to manipulate sensitive user fields during the account creation process.
Who is affected by CVE-2025-48478?
Users of FreeScout versions prior to 1.8.180 are affected by CVE-2025-48478.
What does CVE-2025-48478 exploit?
CVE-2025-48478 exploits insufficient input validation during the user creation process.