CVE-2025-10696
Last modified
CVE-2025-10696 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. OpenSupports exposes an endpoint that allows the list of 'supervised users' for any account to be edited, but it does not validate whether the actor is the owner of that list. A Level 1 staff member can modify the supervision relationship of a third party (the target user), who can then view the tickets of the added 'supervised' users. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
OpenSupports exposes an endpoint that allows the list of 'supervised users' for any account to be edited, but it does not validate whether the actor is the owner of that list. A Level 1 staff member can modify the supervision relationship of a third party (the target user), who can then view the tickets of the added 'supervised' users. This breaks the authorization model and filters the content of other users' tickets.This issue affects OpenSupports: 4.11.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opensupports | Opensupports | 4.11.0 |
References
- https://fluidattacks.com/advisories/stratovariusExploit, Third Party Advisory
- https://fluidattacks.com/advisories/stratovariusExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-10696?
How severe is CVE-2025-10696?
How do I fix CVE-2025-10696?
Are you affected by CVE-2025-10696?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
