CVE 7.1 HIGH

OpenSupports 4.11.0 — Insecure Direct Object Reference in supervised list_CVE-2025-10696

7.1 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

OpenSupports exposes an endpoint that allows the list of 'supervised users' for any account to be edited, but it does not validate whether the actor is the owner of that list. A Level 1 staff member can modify the supervision relationship of a third party (the target user), who can then view the tickets of the added 'supervised' users. This breaks the authorization model and filters the content of other users' tickets.This issue affects OpenSupports: 4.11.0.

Basic Information

ID CVE-2025-10696
Source Fluid Attacks
Published Oct 3, 2025 at 20:35

Affected Product

Vendor OpenSupports
Product OpenSupports
Version 4.11.0
Affected Versions OpenSupports OpenSupports 4.11.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.