FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to deserialization of untrusted data due to insufficient validation. Through the set function, a string with a serialized object can be passed, and when getting an option through the get method, deserialization will occur, which will allow arbitrary code execution This issue has been patched in version 1.8.178.
Metrics
Affected Vendors & Products
References
History
Fri, 30 May 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 29 May 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to deserialization of untrusted data due to insufficient validation. Through the set function, a string with a serialized object can be passed, and when getting an option through the get method, deserialization will occur, which will allow arbitrary code execution This issue has been patched in version 1.8.178. | |
Title | FreeScout Vulnerable to Deserialization of Untrusted Data | |
Weaknesses | CWE-502 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-05-29T15:12:16.578Z
Updated: 2025-05-30T22:03:18.131Z
Reserved: 2025-05-19T15:46:00.398Z
Link: CVE-2025-48389

Updated: 2025-05-30T14:43:26.692Z

Status : Awaiting Analysis
Published: 2025-05-29T16:15:40.330
Modified: 2025-05-30T16:31:03.107
Link: CVE-2025-48389

No data.