Mass Assignment Vulnerability in FreeScout Help Desk Software
CVE-2025-48478
7HIGH
What is CVE-2025-48478?
FreeScout, an open-source help desk and shared mailbox solution, is affected by a mass assignment vulnerability due to inadequate input validation during the user creation process. This flaw permits attackers to manipulate all fields of the User object defined in the $fillable array when a new user is created. Such exploitation can lead to severe security risks. This vulnerability has been addressed in version 1.8.180, emphasizing the need for users to update their software promptly to maintain security integrity.
Affected Version(s)
freescout < 1.8.180