CVE-2025-48482: FreeScout Has Business Logic Errors
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, there is a mass assignment vulnerability. The Customer object is updated using the fill() method, which processes fields such as channel and channelid. However, the fill() method is called with all client-provided data, including unexpected values for channel and channelid, leading to a mass assignment vulnerability. This issue has been patched in version 1.8.180.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48482?
CVE-2025-48482 is considered to have a high severity due to its mass assignment vulnerability affecting the Customer object.
How do I fix CVE-2025-48482?
To fix CVE-2025-48482, upgrade FreeScout to version 1.8.180 or later.
What impact does CVE-2025-48482 have on FreeScout?
CVE-2025-48482 may allow unauthorized users to modify Customer object fields, compromising the integrity of data.
Is my FreeScout installation vulnerable to CVE-2025-48482?
If you are using a version of FreeScout earlier than 1.8.180, your installation is vulnerable to CVE-2025-48482.
What is FreeScout's fill() method in relation to CVE-2025-48482?
The fill() method in FreeScout is responsible for updating Customer object fields but is vulnerable to mass assignment issues prior to version 1.8.180.