CVE-2025-48473

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, when creating a conversation from a message in another conversation, there is no check to ensure that the user has the ability to view this message. Thus, the user can view arbitrary messages from other mailboxes or from other conversations to which they do not have access (access restriction to conversations is implemented by the show_only_assigned_conversations setting, which is also not checked). This issue has been patched in version 1.8.179.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freescout:freescout:*:*:*:*:*:*:*:*

History

11 Jul 2025, 15:28

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-29 16:15

Updated : 2025-07-11 15:28


NVD link : CVE-2025-48473

Mitre link : CVE-2025-48473

CVE.ORG link : CVE-2025-48473


JSON object : View

Products Affected

freescout

  • freescout
CWE
CWE-863

Incorrect Authorization