CVE-2025-48484: FreeScout Vulnerable to Stored XSS
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data in the conversation POST data body. This issue has been patched in version 1.8.178.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48484?
CVE-2025-48484 is classified as a high severity vulnerability due to its potential for Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2025-48484?
To fix CVE-2025-48484, upgrade FreeScout to version 1.8.178 or later to ensure proper input validation and sanitization.
What versions of FreeScout are affected by CVE-2025-48484?
FreeScout versions prior to 1.8.178 are vulnerable to CVE-2025-48484.
What type of vulnerability is CVE-2025-48484?
CVE-2025-48484 is a Cross-Site Scripting (XSS) vulnerability that arises from inadequate input validation.
What are the potential impacts of CVE-2025-48484?
The potential impacts of CVE-2025-48484 include the execution of arbitrary scripts in the context of the user's session.