PT-2025-23171 · Freescout · Freescout
Artem Danilov
+5
·
Published
2025-05-13
·
Updated
2025-07-11
·
CVE-2025-48389
CVSS v2.0
8.7
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:P |
Name of the Vulnerable Software and Affected Versions
FreeScout versions prior to 1.8.178
Description
The issue is related to the deserialization of untrusted data due to insufficient validation, allowing arbitrary code execution. This occurs when a string with a serialized object is passed through the set function and deserialization happens when getting an option through the get method.
Recommendations
For versions prior to 1.8.178, update to version 1.8.178 to patch the vulnerability. As a temporary workaround, consider restricting access to the set and get methods to minimize the risk of exploitation.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freescout