CVE-2025-48485: FreeScout Vulnerable to Stored XSS
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data when an authenticated user updates the profile of an arbitrary customer. This issue has been patched in version 1.8.180.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48485?
The severity of CVE-2025-48485 is classified as medium due to its potential for Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2025-48485?
To fix CVE-2025-48485, upgrade FreeScout to version 1.8.180 or later.
Who is affected by CVE-2025-48485?
All users of FreeScout prior to version 1.8.180 are affected by CVE-2025-48485.
What type of vulnerability is CVE-2025-48485?
CVE-2025-48485 is a Cross-Site Scripting (XSS) vulnerability caused by improper input validation.
What can an attacker achieve with CVE-2025-48485?
An attacker can exploit CVE-2025-48485 to execute arbitrary scripts in the context of an authenticated user's session.