CVE-2025-48482
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
30/05/2025
Last modified:
04/06/2025
Description
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, there is a mass assignment vulnerability. The Customer object is updated using the fill() method, which processes fields such as channel and channel_id. However, the fill() method is called with all client-provided data, including unexpected values for channel and channel_id, leading to a mass assignment vulnerability. This issue has been patched in version 1.8.180.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:freescout:freescout:*:*:*:*:*:*:*:* | 1.8.180 (excluding) |
To consult the complete list of CPE names with products and versions, see this page