CVE-2025-10696
Last modified
CVE-2025-10696 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. OpenSupports exposes an endpoint that allows the list of 'supervised users' for any account to be edited, but it does not validate whether the actor is the owner of that list. A Level 1 staff member can modify the supervision relationship of a third party (the target user), who can then view the tickets of the added 'supervised' users. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
OpenSupports exposes an endpoint that allows the list of 'supervised users' for any account to be edited, but it does not validate whether the actor is the owner of that list. A Level 1 staff member can modify the supervision relationship of a third party (the target user), who can then view the tickets of the added 'supervised' users. This breaks the authorization model and filters the content of other users' tickets.This issue affects OpenSupports: 4.11.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opensupports | Opensupports | 4.11.0 |
References
- https://fluidattacks.com/advisories/stratovariusExploit, Third Party Advisory
- https://fluidattacks.com/advisories/stratovariusExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-10696?
How severe is CVE-2025-10696?
How do I fix CVE-2025-10696?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-10690The Goza - Nonprofit Charity WordPress Theme theme for WordP…9.8
- CVE-2025-10691The Easy Email Subscription plugin for WordPress is vulnerab…4.3
- CVE-2025-10692The endpoint POST /api/staff/get-new-tickets concatenates th…7.1
- CVE-2025-10693When SmartStart Inclusion fails during the onboarding of a Z…7.6
- CVE-2025-10694The User Feedback – Create Interactive Feedback Form, User S…5.3
- CVE-2025-10695Two unauthenticated diagnostic endpoints allow arbitrary bac…5.3
- CVE-2025-10699A vulnerability was reported in the Lenovo LeCloud client ap…6
- CVE-2025-1070CWE-434: Unrestricted Upload of File with Dangerous Type vul…8.1
- CVE-2025-10700The Ally – Web Accessibility & Usability plugin for WordPres…4.3
- CVE-2025-10701The Time Clock – A WordPress Employee & Volunteer Time Clock…6.4
- CVE-2025-10702Improper Control of Generation of Code ('Code Injection') vu…8.6
- CVE-2025-10703Improper Control of Generation of Code ('Code Injection') vu…8.6
Are you affected by CVE-2025-10696?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
