PT-2025-23178 · Freescout · Freescout

Artem Danilov

+5

·

Published

2025-05-13

·

Updated

2025-07-02

·

CVE-2025-48474

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions FreeScout versions prior to 1.8.180
Description The application incorrectly checks user access rights for conversations. Users with show only assigned conversations enabled can assign themselves to an arbitrary conversation from the mailbox to which they have access, thereby bypassing the restriction on viewing conversations.
Recommendations For versions prior to 1.8.180, update to version 1.8.180 to resolve the issue. As a temporary workaround, consider disabling the feature that allows users to assign themselves to conversations until the update is applied. Restrict access to the mailbox to minimize the risk of exploitation.

Exploit

Fix

LPE

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-06950
CVE-2025-48474
GHSA-9WC4-VCHW-MR3M

Affected Products

Freescout