CVE-2025-48471

CRITICAL

FreeScout <1.8.179 - RCE

Title source: llm
STIX 2.1

Description

FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, the application does not check or performs insufficient checking of files uploaded to the application. This allows files to be uploaded with the phtml and phar extensions, which can lead to remote code execution if the Apache web server is used. This issue has been patched in version 1.8.179.

Scores

CVSS v3 9.8
EPSS 0.0290
EPSS Percentile 86.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-434
Status published
Products (1)
freescout/freescout < 1.8.179
Published May 29, 2025
Tracked Since Feb 18, 2026