CVE-2025-48489: FreeScout Vulnerable to Stored XSS
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to insufficient data validation and sanitization during data reception. This issue has been patched in version 1.8.180.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48489?
CVE-2025-48489 has a medium severity level due to its potential for Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2025-48489?
To fix CVE-2025-48489, upgrade to FreeScout version 1.8.180 or later where the vulnerability has been patched.
What type of vulnerability is CVE-2025-48489?
CVE-2025-48489 is a Cross-Site Scripting (XSS) vulnerability caused by insufficient data validation and sanitization.
Which versions of FreeScout are affected by CVE-2025-48489?
FreeScout versions prior to 1.8.180 are affected by CVE-2025-48489.
Why is CVE-2025-48489 a security concern?
CVE-2025-48489 is a security concern because it allows attackers to execute malicious scripts in the context of a user's session, compromising data integrity and user safety.