CVE-2025-10696

Source
https://cve.org/CVERecord?id=CVE-2025-10696
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-10696.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-10696
Published
2025-10-03T20:35:41.279Z
Modified
2026-07-15T01:49:01.641876887Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
OpenSupports 4.11.0 — Insecure Direct Object Reference in supervised list
Details

OpenSupports exposes an endpoint that allows the list of 'supervised users' for any account to be edited, but it does not validate whether the actor is the owner of that list. A Level 1 staff member can modify the supervision relationship of a third party (the target user), who can then view the tickets of the added 'supervised' users. This breaks the authorization model and filters the content of other users' tickets.This issue affects OpenSupports: 4.11.0.

Database specific
{
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/10xxx/CVE-2025-10696.json",
    "cna_assigner": "Fluid Attacks"
}
References

Affected packages

Git / github.com/opensupports/opensupports

Affected ranges

Type
GIT
Repo
https://github.com/opensupports/opensupports
Events
Database specific
{
    "cpe": "cpe:2.3:a:opensupports:opensupports:4.11.0:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "4.11.0"
        },
        {
            "last_affected": "4.11.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "CPE_STRING"
    ]
}

Affected versions

4.*
4.11.0
v4.*
v4.11.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-10696.json"