CVE-2025-48487

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when creating a translation of a phrase that appears in a flash-message after a completed action, it is possible to inject a payload to exploit XSS vulnerability. This issue has been patched in version 1.8.180.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freescout:freescout:*:*:*:*:*:*:*:*

History

04 Jun 2025, 19:57

Type Values Removed Values Added
References () https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-wg2q-m2fj-x6j4 - () https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-wg2q-m2fj-x6j4 - Exploit, Vendor Advisory
CPE cpe:2.3:a:freescout:freescout:*:*:*:*:*:*:*:*
First Time Freescout
Freescout freescout
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8

30 May 2025, 16:31

Type Values Removed Values Added
Summary
  • (es) FreeScout es un servicio de asistencia gratuito y autoalojado, con buzón compartido. Antes de la versión 1.8.180, al crear la traducción de una frase que aparece en un mensaje flash tras una acción completada, era posible inyectar un payload para explotar la vulnerabilidad XSS. Este problema se ha corregido en la versión 1.8.180.

30 May 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-30 07:15

Updated : 2025-06-04 19:57


NVD link : CVE-2025-48487

Mitre link : CVE-2025-48487

CVE.ORG link : CVE-2025-48487


JSON object : View

Products Affected

freescout

  • freescout
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')