Mass Assignment Vulnerability in FreeScout Help Desk Software
CVE-2025-48482
5.3MEDIUM
What is CVE-2025-48482?
FreeScout, a free self-hosted help desk platform, is affected by a mass assignment vulnerability prior to version 1.8.180. This vulnerability arises from the usage of the fill() method, which incorrectly processes client-provided data, including unexpected values for critical fields like channel and channel_id. As a result, unauthorized updates to the Customer object can occur, leading to potential data exposure. Users are advised to update to the latest version to mitigate this security risk.
Affected Version(s)
freescout < 1.8.180