Mass Assignment Vulnerability in FreeScout Help Desk Software
CVE-2025-48482

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
30 May 2025

What is CVE-2025-48482?

FreeScout, a free self-hosted help desk platform, is affected by a mass assignment vulnerability prior to version 1.8.180. This vulnerability arises from the usage of the fill() method, which incorrectly processes client-provided data, including unexpected values for critical fields like channel and channel_id. As a result, unauthorized updates to the Customer object can occur, leading to potential data exposure. Users are advised to update to the latest version to mitigate this security risk.

Affected Version(s)

freescout < 1.8.180

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48482 : Mass Assignment Vulnerability in FreeScout Help Desk Software