CVE-2025-48485
- EPSS 0.17%
- Veröffentlicht 30.05.2025 06:16:50
- Zuletzt bearbeitet 04.06.2025 14:32:26
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data when an authenticated us...
CVE-2025-48484
- EPSS 0.15%
- Veröffentlicht 30.05.2025 04:59:23
- Zuletzt bearbeitet 04.06.2025 15:34:51
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data in the conversation POST...
CVE-2025-48483
- EPSS 0.07%
- Veröffentlicht 30.05.2025 04:58:48
- Zuletzt bearbeitet 04.06.2025 15:35:21
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application is vulnerable to Cross-Site Scripting (XSS) attacks due to incorrect input validation and sanitization of user-input data during mail signature sa...
CVE-2025-48482
- EPSS 0.09%
- Veröffentlicht 30.05.2025 04:35:30
- Zuletzt bearbeitet 04.06.2025 15:35:32
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, there is a mass assignment vulnerability. The Customer object is updated using the fill() method, which processes fields such as channel and channel_id. However, ...
CVE-2025-48481
- EPSS 0.14%
- Veröffentlicht 30.05.2025 04:35:03
- Zuletzt bearbeitet 04.06.2025 15:35:47
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an attacker with an unactivated email invitation containing invite_hash, can exploit this vulnerability to self-activate their account, despite it being blocked o...
CVE-2025-48480
- EPSS 0.11%
- Veröffentlicht 30.05.2025 04:34:34
- Zuletzt bearbeitet 04.06.2025 15:35:54
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an authorized user with the administrator role or with the privilege User::PERM_EDIT_USERS can create a user, specifying the path to the user's avatar ../.htacces...
CVE-2025-48479
- EPSS 0.11%
- Veröffentlicht 30.05.2025 04:34:09
- Zuletzt bearbeitet 04.06.2025 15:36:04
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the laravel-translation-manager package does not correctly validate user input, enabling the deletion of any directory, given sufficient access rights. This issue...
CVE-2025-48478
- EPSS 0.13%
- Veröffentlicht 30.05.2025 04:32:12
- Zuletzt bearbeitet 04.06.2025 15:36:13
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, insufficient input validation during user creation has resulted in a mass assignment vulnerability, allowing an attacker to manipulate all fields of the object, w...
CVE-2025-48477
- EPSS 0.11%
- Veröffentlicht 30.05.2025 04:31:42
- Zuletzt bearbeitet 04.06.2025 15:36:20
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, the application's logic requires the user to perform a correct sequence of actions to implement a functional capability, but the application allows access to the ...
CVE-2025-48476
- EPSS 0.14%
- Veröffentlicht 30.05.2025 04:30:09
- Zuletzt bearbeitet 04.06.2025 15:36:28
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, when adding and editing user records using the fill() method, there is no check for the absence of the password field in the data coming from the user, which lead...