CVE-2025-48875

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-48875
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-48875.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-48875
Aliases
  • GHSA-mjjx-rv96-w9hq
Published
2025-05-30T07:15:24Z
Modified
2025-05-31T04:29:13.194991Z
Summary
[none]
Details

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, the system's incorrect validation of lastname and firstname during profile data updates allows for the injection of arbitrary JavaScript code, which will be executed in a flesh-message when the data is deleted, potentially leading to a Cross-Site Scripting (XSS) vulnerability. This issue has been patched in version 1.8.181.

References

Affected packages

Git / github.com/freescout-help-desk/freescout

Affected ranges

Type
GIT
Repo
https://github.com/freescout-help-desk/freescout
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.7.29