Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2025-28219 | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to deserialization of untrusted data due to insufficient validation. Through the set function, a string with a serialized object can be passed, and when getting an option through the get method, deserialization will occur, which will allow arbitrary code execution This issue has been patched in version 1.8.178. | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Fri, 11 Jul 2025 15:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Freescout
         Freescout freescout  | 
|
| CPEs | cpe:2.3:a:freescout:freescout:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Freescout
         Freescout freescout  | 
|
| Metrics | 
        
        cvssV3_1
         
  | 
Fri, 30 May 2025 22:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Thu, 29 May 2025 15:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.178, FreeScout is vulnerable to deserialization of untrusted data due to insufficient validation. Through the set function, a string with a serialized object can be passed, and when getting an option through the get method, deserialization will occur, which will allow arbitrary code execution This issue has been patched in version 1.8.178. | |
| Title | FreeScout Vulnerable to Deserialization of Untrusted Data | |
| Weaknesses | CWE-502 | |
| References | 
         | |
| Metrics | 
        
        cvssV4_0
         
  | 
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-30T22:03:18.131Z
Reserved: 2025-05-19T15:46:00.398Z
Link: CVE-2025-48389
Updated: 2025-05-30T14:43:26.692Z
Status : Analyzed
Published: 2025-05-29T16:15:40.330
Modified: 2025-07-11T15:26:53.300
Link: CVE-2025-48389
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD