Cross-Site Scripting Vulnerability in FreeScout Help Desk Solution
CVE-2025-48875
4.6MEDIUM
What is CVE-2025-48875?
FreeScout, a free self-hosted help desk software, has a vulnerability due to inadequate validation of user input fields 'last_name' and 'first_name' during profile updates. This flaw allows attackers to inject arbitrary JavaScript code that can be executed when user data is deleted, leading to a significant Cross-Site Scripting (XSS) threat. The issue has been addressed in version 1.8.181.
Affected Version(s)
freescout < 1.8.181