XSS Vulnerability in FreeScout Help Desk Software
CVE-2025-48487
6MEDIUM
What is CVE-2025-48487?
FreeScout, a self-hosted help desk solution, was identified to have a security issue prior to version 1.8.180. This vulnerability allows an attacker to inject malicious scripts via crafted translations of flash-message phrases following completed actions. Successful exploitation could lead to unauthorized actions within the user's session, potentially exposing sensitive data. Users are strongly encouraged to update to version 1.8.180 or later to mitigate this risk.
Affected Version(s)
freescout < 1.8.180