CVE-2025-48481: FreeScout Has Business Logic Errors
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an attacker with an unactivated email invitation containing invitehash, can exploit this vulnerability to self-activate their account, despite it being blocked or deleted, by leveraging the invitation link from the email to gain initial access to the account. This issue has been patched in version 1.8.180.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48481?
CVE-2025-48481 is considered a high severity vulnerability due to the potential for unauthorized account activation.
How do I fix CVE-2025-48481?
To fix CVE-2025-48481, update FreeScout to version 1.8.180 or later.
What causes CVE-2025-48481?
CVE-2025-48481 is caused by inadequate validation of email invitations allowing attackers to self-activate accounts.
Who is affected by CVE-2025-48481?
Any instances of FreeScout prior to version 1.8.180 are affected by CVE-2025-48481.
Can I mitigate risk from CVE-2025-48481 without updating?
Mitigating risk from CVE-2025-48481 without updating is challenging; disabling email invitations may provide temporary relief.