CVE-2025-48479: FreeScout Has Business Logic Errors
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the laravel-translation-manager package does not correctly validate user input, enabling the deletion of any directory, given sufficient access rights. This issue has been patched in version 1.8.180.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48479?
CVE-2025-48479 is considered a high severity vulnerability due to its potential for allowing directory deletion with sufficient access rights.
How do I fix CVE-2025-48479?
To fix CVE-2025-48479, you should upgrade your FreeScout installation to version 1.8.181 or later, where the issue has been patched.
What software versions are affected by CVE-2025-48479?
All versions of FreeScout prior to 1.8.180 are affected by CVE-2025-48479.
What is the root cause of CVE-2025-48479?
The root cause of CVE-2025-48479 is improper input validation in the laravel-translation-manager package used by FreeScout.
Can CVE-2025-48479 be exploited remotely?
Yes, CVE-2025-48479 can be exploited remotely if an attacker has sufficient access rights to the affected FreeScout installation.