Back to search
CVE-2025-48388
Published: May 29, 2025
Modified: May 29, 2025
PUBLISHED
Description
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, the application performs insufficient validation of user-supplied data, which is used as arguments to string formatting functions. As a result, an attacker can pass a string containing special symbols (\r, \n, \t)to the application. This issue has been patched in version 1.8.178.
| Vendor | Product | Versions |
|---|---|---|
freescout-help-desk | freescout | affected < 1.8.178 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now