PT-2025-23173 · Apache+1 · Apache Web Server+1

Artem Danilov

+5

·

Published

2025-05-13

·

Updated

2025-06-01

·

CVE-2025-48471

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeScout versions prior to 1.8.179
Description The issue concerns insufficient checking of files uploaded to the application, allowing files with phtml and phar extensions to be uploaded. This can lead to remote code execution if the Apache web server is used.
Recommendations For versions prior to 1.8.179, update to version 1.8.179 to resolve the issue. As a temporary workaround, consider restricting file uploads or disabling the upload feature until the update is applied.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2025-06947
CVE-2025-48471
GHSA-H2F3-932H-V38J

Affected Products

Apache Web Server
Freescout