Access Control Flaw in FreeScout Help Desk Software
CVE-2025-48475
What is CVE-2025-48475?
FreeScout, a self-hosted help desk solution, has a significant access control issue that allows unauthorized users to view and edit client details. This vulnerability occurs because the system lacks adequate checks for user permissions concerning client visibility. Although a configuration setting, 'limit_user_customer_visibility', can enforce limitations, there are scenarios where this setting is not respected, leading to potential data exposure. This flaw was rectified in version 1.8.180, emphasizing the importance of keeping software updated to ensure security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
freescout < 1.8.180
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
