CVE-2025-48388
Severity CVSS v4.0:
HIGH
Type:
CWE-93
Improper Neutralization of CRLF Sequences ('CRLF Injection')
Publication date:
29/05/2025
Last modified:
11/07/2025
Description
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application performs insufficient validation of user-supplied data, which is used as arguments to string formatting functions. As a result, an attacker can pass a string containing special symbols (\r, \n, \t)to the application. This issue has been patched in version 1.8.178.
Impact
Base Score 4.0
7.00
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:freescout:freescout:*:*:*:*:*:*:*:* | 1.8.178 (excluding) |
To consult the complete list of CPE names with products and versions, see this page