Medium6.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:L/SA:L

PT-2025-57: Stored XSS leads to CSRF in FreeScout

Error type:

  • CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Vulnerability vector:

  • Base vulnerability score (CVSSv4.0): CVSS:4.0/ AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:L/SA:L

  • Severity (CVSSv4.0): 6.3 (Medium)

Description:

The vulnerability was identified in FreeScout, versions v.1.8.173 and 1.8.174.

The discovered vulnerability allows an attacker to store an XSS payload that later triggers forged requests on behalf of the victim (CSRF), broadening the impact of the attack.

Vulnerability status: Confirmed by vendor

Date of vulnerability remediation: 23.05.2025

Recommendations:

  • Update to version 1.8.180 or higher

Additional information: Security advisory

Researcher: Ilya Tsaturov, Daniil Satyaev, Roman Cheremnykh, Artem Deikov, Artem Danilov, Stanislav Gleym (Positive Technologies)

Identifiers:

CVE-2025-48483

BDU:2025-06959

Vendor:

FreeScout

Vulnerable product:

FreeScout

Vulnerable versions:

v.1.8.173 and 1.8.174