Remote Code Execution Vulnerability in FreeScout by FreeScout
CVE-2025-48471
7HIGH
What is CVE-2025-48471?
FreeScout, a self-hosted help desk solution, contains a vulnerability that permits insufficient verification of files uploaded to the application. This weakness allows malicious files with the phtml and phar extensions to be uploaded, potentially leading to remote code execution, particularly when hosted on an Apache web server. Users are advised to update to version 1.8.179 or later to mitigate this risk.
Affected Version(s)
freescout < 1.8.179