PT-2026-51584 · Unknown · Fossbilling

CVE-2025-64105

·

Published

2026-06-23

·

Updated

2026-06-25

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions FOSSBilling versions 0.6.21 through 0.7.2
Description An Insecure Direct Object Reference (IDOR) exists in the support ticket creation workflow. An authenticated client can create a support ticket that references an order belonging to another client by manipulating the rel id variable when rel type is set to order. This occurs because the ticketCreateForClient() function fails to verify order ownership for non-upgrade tasks. This flaw could lead to integrity and confidentiality issues, as staff members might be misled into performing actions, such as cancellations or upgrades, on the incorrect order. While order IDs may appear in the ticket context, there is no direct client-to-client exposure of order data.
Recommendations Update to version 0.8.0.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-64105
GHSA-RCR8-P92P-9887

Affected Products

Fossbilling