PT-2025-23178 · Freescout · Freescout
Artem Danilov
+5
·
Published
2025-05-13
·
Updated
2025-07-02
·
CVE-2025-48474
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
FreeScout versions prior to 1.8.180
Description
The application incorrectly checks user access rights for conversations. Users with
show only assigned conversations enabled can assign themselves to an arbitrary conversation from the mailbox to which they have access, thereby bypassing the restriction on viewing conversations.Recommendations
For versions prior to 1.8.180, update to version 1.8.180 to resolve the issue. As a temporary workaround, consider disabling the feature that allows users to assign themselves to conversations until the update is applied. Restrict access to the mailbox to minimize the risk of exploitation.
Exploit
Fix
LPE
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freescout