Cross-Site Scripting Vulnerability in FreeScout Help Desk Application
CVE-2025-48489
What is CVE-2025-48489?
The FreeScout application, a widely used self-hosted help desk solution, has a vulnerability that allows attackers to execute Cross-Site Scripting (XSS) attacks. This weakness stems from insufficient validation and sanitization of data received by the application. Users of FreeScout prior to version 1.8.180 are at risk, as this allows malicious scripts to be injected, potentially compromising user sessions and leading to unauthorized access or data manipulation. It is crucial for all users to upgrade to version 1.8.180 or later to mitigate this threat.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
freescout < 1.8.180
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
