Cross-Site Scripting Vulnerability in FreeScout Help Desk Software
CVE-2025-48486
6.1MEDIUM
What is CVE-2025-48486?
FreeScout, a popular self-hosted help desk and shared mailbox solution, has a vulnerability due to insufficient input validation and sanitization in functions such as \Session::flash and __. This flaw allows for the execution of untrusted user input, leading to potential XSS attacks. The issue has been remediated in version 1.8.180, urging users to upgrade to ensure their systems are secure.
Affected Version(s)
freescout < 1.8.180