Medium6.1
AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N

PT-2025-117: Server‑Side Request Forgery (SSRF) in FreeScout

Error type:

  • CWE-918:Server-Side Request Forgery (SSRF)

Vulnerability vector:

  • Base vulnerability score (CVSSv4.0): CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
  • Severity (CVSSv4.0): 6.1 (Medium)

Description:

The vulnerability was identified in FreeScout , versions 1.8.182.

The discovered vulnerability allows an attacker to make requests to both local and external resources, mask their own IP address and retrieve data from protected network segments.

Vulnerability status: Confirmed by vendor

Date of vulnerability remediation: 08.08.2025

Recommendations:

Additional information: Security advisory, Press release

Researcher: Daniil Satyaev, Roman Cheremnykh, Artem Danilov (Positive Technologies)

Identifiers:

BDU:2025-13065

Vendor:

FreeScout

Vulnerable product:

FreeScout

Vulnerable versions:

1.8.182