CVE-2025-10696 describes an authorization bypass vulnerability in OpenSupports version 4.11.0. A low-privileged staff member can exploit an exposed endpoint to modify the "supervised users" list of any account without proper ownership validation. This allows the attacker to view tickets belonging to other users, compromising data confidentiality and integrity. Rated as Medium severity (CVSS 5.4), the vulnerability has a low attack complexity and requires only low privileges, but does not impact availability. The potential impact is limited to disclosure and modification of sensitive information. Currently, there is no evidence of active exploitation, nor are there publicly available exploit codes or Metasploit/Nuclei modules. Community discussion and media coverage for this CVE are minimal, indicating a low level of public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.11.0CPE matchmatch criteria | cpe:2.3:a:opensupports:opensupports:4.11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.