PT-2025-23265 · Freescout · Freescout
Artem Danilov
+5
·
Published
2025-05-13
·
Updated
2025-06-04
·
CVE-2025-48880
CVSS v3.1
6.6
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FreeScout versions prior to 1.8.181
Description
FreeScout is a free self-hosted help desk and shared mailbox. A race condition could occur when an administrative account is deleting a user. This issue has been patched in version 1.8.181.
Recommendations
For versions prior to 1.8.181, update to version 1.8.181 to resolve the issue.
As a temporary workaround, consider restricting the deletion of users by administrative accounts until a patch is available.
Exploit
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freescout