Access Control Flaw in FreeScout Help Desk Software
CVE-2025-48475
5.3MEDIUM
What is CVE-2025-48475?
FreeScout, a self-hosted help desk solution, has a significant access control issue that allows unauthorized users to view and edit client details. This vulnerability occurs because the system lacks adequate checks for user permissions concerning client visibility. Although a configuration setting, 'limit_user_customer_visibility', can enforce limitations, there are scenarios where this setting is not respected, leading to potential data exposure. This flaw was rectified in version 1.8.180, emphasizing the importance of keeping software updated to ensure security.
Affected Version(s)
freescout < 1.8.180