FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to deserialization of untrusted data due to insufficient validation. Through the set function, a string with a serialized object can be passed, and when getting an option through the get method, deserialization will occur, which will allow arbitrary code execution This issue has been patched in version 1.8.178.
References
Configurations
History
11 Jul 2025, 15:26
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.2 |
References | () https://github.com/freescout-help-desk/freescout/commit/f7548a7076a0b6e109001069d6be223fbd96c61e - Patch | |
References | () https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-jmpv-8q3h-2m8v - Exploit, Vendor Advisory | |
First Time |
Freescout freescout
Freescout |
|
CPE | cpe:2.3:a:freescout:freescout:*:*:*:*:*:*:*:* |
30 May 2025, 16:31
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
29 May 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-29 16:15
Updated : 2025-07-11 15:26
NVD link : CVE-2025-48389
Mitre link : CVE-2025-48389
CVE.ORG link : CVE-2025-48389
JSON object : View
Products Affected
freescout
- freescout
CWE
CWE-502
Deserialization of Untrusted Data