MEDIUM
FreeScout has Race Condition When Deleting Users
Published May 30, 2025
5.1
MEDIUMCVSS 4.0
EPSS 0.39%
Description
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, when an administrative account is a deleting a user, there is the the possibility of a race condition occurring. This issue has been patched in version 1.8.181.
Affected products
-
- Version < 1.8.181StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Freescout-Help-Desk | Freescout | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-28272 Advisory
- https://github.com/freescout-help-desk/freescout/commit/3f5bb2841f7de3303bc3cb00930a28440754d122 x_refsource_MISCPatch
- https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-9vf2-mg4j-4v7f x_refsource_CONFIRMExploitVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-28272 | Advisory | |
| https://github.com/freescout-help-desk/freescout/commit/3f5bb2841f7de3303bc3cb00930a28440754d122 | x_refsource_MISCPatch | |
| https://github.com/freescout-help-desk/freescout/security/advisories/GHSA-9vf2-mg4j-4v7f | x_refsource_CONFIRMExploitVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 30, 2025
Updated May 30, 2025
Reserved May 27, 2025
Link CVE-2025-48880
CISA Vulnrichment
Updated May 30, 2025
ENISA EUVD
EUVD-2025-28272 Assigner GitHub_M
Published May 30, 2025
Updated May 30, 2025
Exploited since n/a
Link EUVD-2025-28272