PT-2025-23265 · Freescout · Freescout

·

CVE-2025-48880

·

Published

2025-05-13

·

Updated

2025-06-04

CVSS v3.1

6.6

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeScout versions prior to 1.8.181
Description FreeScout is a free self-hosted help desk and shared mailbox. A race condition could occur when an administrative account is deleting a user. This issue has been patched in version 1.8.181.
Recommendations For versions prior to 1.8.181, update to version 1.8.181 to resolve the issue. As a temporary workaround, consider restricting the deletion of users by administrative accounts until a patch is available.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06967
CVE-2025-48880
GHSA-9VF2-MG4J-4V7F

Affected Products

Freescout