Cross-Site Scripting Vulnerability in FreeScout Help Desk Application
CVE-2025-48489
4.6MEDIUM
What is CVE-2025-48489?
The FreeScout application, a widely used self-hosted help desk solution, has a vulnerability that allows attackers to execute Cross-Site Scripting (XSS) attacks. This weakness stems from insufficient validation and sanitization of data received by the application. Users of FreeScout prior to version 1.8.180 are at risk, as this allows malicious scripts to be injected, potentially compromising user sessions and leading to unauthorized access or data manipulation. It is crucial for all users to upgrade to version 1.8.180 or later to mitigate this threat.
Affected Version(s)
freescout < 1.8.180