Mass Assignment Vulnerability in FreeScout Help Desk Software
CVE-2025-48478

7HIGH

Key Information:

Status
Vendor
CVE Published:
30 May 2025

What is CVE-2025-48478?

FreeScout, an open-source help desk and shared mailbox solution, is affected by a mass assignment vulnerability due to inadequate input validation during the user creation process. This flaw permits attackers to manipulate all fields of the User object defined in the $fillable array when a new user is created. Such exploitation can lead to severe security risks. This vulnerability has been addressed in version 1.8.180, emphasizing the need for users to update their software promptly to maintain security integrity.

Affected Version(s)

freescout < 1.8.180

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48478 : Mass Assignment Vulnerability in FreeScout Help Desk Software