CVE-2025-48480: FreeScout Has Business Logic Errors
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an authorized user with the administrator role or with the privilege User::PERMEDITUSERS can create a user, specifying the path to the user's avatar ../.htaccess during creation, and then delete the user's avatar, resulting in the deletion of the file .htaccess in the folder /storage/app/public. This issue has been patched in version 1.8.180.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48480?
CVE-2025-48480 has a high severity level due to the potential for unauthorized file manipulation.
How do I fix CVE-2025-48480?
To fix CVE-2025-48480, upgrade FreeScout to version 1.8.180 or later.
Who is affected by CVE-2025-48480?
All users of FreeScout prior to version 1.8.180 are affected by CVE-2025-48480.
What types of attacks can CVE-2025-48480 enable?
CVE-2025-48480 can potentially allow an attacker to overwrite critical system files.
What roles are involved in exploiting CVE-2025-48480?
An authorized user with either the administrator role or the privilege User::PERM_EDIT_USERS can exploit CVE-2025-48480.