PT-2025-23171 · Freescout · Freescout

Artem Danilov

+5

·

Published

2025-05-13

·

Updated

2025-07-11

·

CVE-2025-48389

CVSS v2.0
8.7
VectorAV:N/AC:L/Au:S/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions FreeScout versions prior to 1.8.178
Description The issue is related to the deserialization of untrusted data due to insufficient validation, allowing arbitrary code execution. This occurs when a string with a serialized object is passed through the set function and deserialization happens when getting an option through the get method.
Recommendations For versions prior to 1.8.178, update to version 1.8.178 to patch the vulnerability. As a temporary workaround, consider restricting access to the set and get methods to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2025-06945
CVE-2025-48389
GHSA-JMPV-8Q3H-2M8V

Affected Products

Freescout