PT-2025-23245 · Unknown+1 · Laravel Translation Manager+1

Artem Danilov

+5

·

Published

2025-05-13

·

Updated

2025-06-04

·

CVE-2025-48479

CVSS v2.0

8.7

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions FreeScout versions prior to 1.8.180
Description The issue concerns the laravel-translation-manager package in FreeScout, which does not correctly validate user input. This enables the deletion of any directory, given sufficient access rights.
Recommendations For versions prior to 1.8.180, update to version 1.8.180 to patch the vulnerability in the laravel-translation-manager package. As a temporary workaround, consider restricting access rights to minimize the risk of unauthorized directory deletion.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-06955
CVE-2025-48479
GHSA-627H-PC3C-W68H

Affected Products

Freescout
Laravel Translation Manager