FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data during mail signature sanitization. An attacker can inject arbitrary HTML code, including JavaScript scripts, into the page processed by the user's browser, allowing them to steal sensitive data, hijack user sessions, or conduct other malicious activities. Additionally, if an administrator accesses one of these emails with a modified signature, it could result in a subsequent Cross-Site Request Forgery (CSRF) vulnerability. This issue has been patched in version 1.8.180.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Jun 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Freescout
Freescout freescout |
|
CPEs | cpe:2.3:a:freescout:freescout:*:*:*:*:*:*:*:* | |
Vendors & Products |
Freescout
Freescout freescout |
|
Metrics |
cvssV3_1
|
Fri, 30 May 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 30 May 2025 05:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data during mail signature sanitization. An attacker can inject arbitrary HTML code, including JavaScript scripts, into the page processed by the user's browser, allowing them to steal sensitive data, hijack user sessions, or conduct other malicious activities. Additionally, if an administrator accesses one of these emails with a modified signature, it could result in a subsequent Cross-Site Request Forgery (CSRF) vulnerability. This issue has been patched in version 1.8.180. | |
Title | FreeScout Stored XSS leads to CSRF | |
Weaknesses | CWE-352 CWE-79 |
|
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-05-30T04:58:48.648Z
Updated: 2025-05-30T22:00:59.493Z
Reserved: 2025-05-22T12:11:39.119Z
Link: CVE-2025-48483

Updated: 2025-05-30T14:39:58.333Z

Status : Analyzed
Published: 2025-05-30T05:15:23.330
Modified: 2025-06-04T15:35:21.950
Link: CVE-2025-48483

No data.