CVE-2025-48487: FreeScout Vulnerable to Stored XSS
Published May 30, 2025
·Updated
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when creating a translation of a phrase that appears in a flash-message after a completed action, it is possible to inject a payload to exploit XSS vulnerability. This issue has been patched in version 1.8.180.
Affected Software
2 affected components
Freescout freescout<1.8.180
Freescout freescout<1.8.180
Event History
May 30, 2025
CVE Published
via MITRE·06:17 AM
Data Sourced
via MITRE·06:17 AM
DescriptionWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-48487?
CVE-2025-48487 has a medium severity level due to its potential for XSS exploitation.
2
How do I fix CVE-2025-48487?
To fix CVE-2025-48487, upgrade to FreeScout version 1.8.180 or later.
3
What impact does CVE-2025-48487 have on FreeScout?
CVE-2025-48487 allows attackers to inject malicious scripts into flash messages after completed actions.
4
Is my FreeScout installation vulnerable to CVE-2025-48487?
If you are using FreeScout version prior to 1.8.180, your installation is vulnerable to CVE-2025-48487.
5
When was CVE-2025-48487 first reported?
CVE-2025-48487 was reported prior to the release of version 1.8.180 of FreeScout.