Cross-Site Scripting Vulnerability in FreeScout Help Desk Application
CVE-2025-48489

4.6MEDIUM

Key Information:

Status
Vendor
CVE Published:
30 May 2025

What is CVE-2025-48489?

The FreeScout application, a widely used self-hosted help desk solution, has a vulnerability that allows attackers to execute Cross-Site Scripting (XSS) attacks. This weakness stems from insufficient validation and sanitization of data received by the application. Users of FreeScout prior to version 1.8.180 are at risk, as this allows malicious scripts to be injected, potentially compromising user sessions and leading to unauthorized access or data manipulation. It is crucial for all users to upgrade to version 1.8.180 or later to mitigate this threat.

Affected Version(s)

freescout < 1.8.180

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48489 : Cross-Site Scripting Vulnerability in FreeScout Help Desk Application