CVE-2025-48486: FreeScout Vulnerable to Stored XSS
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the cross-site scripiting (XSS) vulnerability is caused by the lack of input validation and sanitization in both \Session::flash and , allowing user input to be executed without proper filtering. This issue has been patched in version 1.8.180.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48486?
CVE-2025-48486 has been identified as a medium severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-48486?
To fix CVE-2025-48486, upgrade FreeScout to version 1.8.180 or later.
What causes CVE-2025-48486?
CVE-2025-48486 is caused by insufficient input validation and sanitization in FreeScout's \Session::flash and __ methods.
Who is affected by CVE-2025-48486?
Individuals or organizations using FreeScout versions prior to 1.8.180 are affected by CVE-2025-48486.
What are the potential consequences of CVE-2025-48486?
The consequences of CVE-2025-48486 include the potential for attackers to execute arbitrary JavaScript in the context of the user's browser.