Back to Database
Status published
Medium
CVE-2025-48880
FreeScout has Race Condition When Deleting Users
Vulnerability Description
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.181, when an administrative account is a deleting a user, there is the the possibility of a race condition occurring. This issue has been patched in version 1.8.181.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-48880
Credits & Attribution
No credits recorded in the NVD database.
References
More from freescout-help-desk
View All →CVE-2025-58163
FreeScout's deserialization of untrusted data can lead to Remote Code Execution
High
8.6
CVE-2025-54366
FreeScout's deserialization of untrusted data leads to Remote Code Execution
High
8.6
CVE-2025-48875
FreeScout Vulnerable to Stored XSS
Medium
4.6
CVE-2025-48489
FreeScout Vulnerable to Stored XSS
Medium
4.6
CVE-2025-48488
FreeScout Vulnerable to Stored XSS
Medium
4.6
Affected Vendor
freescout-help-desk
View all reports →Affected Software
freescout
Vulnerable Versions:
< 1.8.181
Timeline
Official Publish:
May 30th, 2025
Last Modified:
May 30th, 2025
Added to House:
July 22nd, 2026