Access Control Flaw in FreeScout Help Desk Software
CVE-2025-48475

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
29 May 2025

What is CVE-2025-48475?

FreeScout, a self-hosted help desk solution, has a significant access control issue that allows unauthorized users to view and edit client details. This vulnerability occurs because the system lacks adequate checks for user permissions concerning client visibility. Although a configuration setting, 'limit_user_customer_visibility', can enforce limitations, there are scenarios where this setting is not respected, leading to potential data exposure. This flaw was rectified in version 1.8.180, emphasizing the importance of keeping software updated to ensure security.

Affected Version(s)

freescout < 1.8.180

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48475 : Access Control Flaw in FreeScout Help Desk Software