PT-2026-51584 · Unknown · Fossbilling
CVE-2025-64105
·
Published
2026-06-23
·
Updated
2026-06-25
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
FOSSBilling versions 0.6.21 through 0.7.2
Description
An Insecure Direct Object Reference (IDOR) exists in the support ticket creation workflow. An authenticated client can create a support ticket that references an order belonging to another client by manipulating the
rel id variable when rel type is set to order. This occurs because the ticketCreateForClient() function fails to verify order ownership for non-upgrade tasks. This flaw could lead to integrity and confidentiality issues, as staff members might be misled into performing actions, such as cancellations or upgrades, on the incorrect order. While order IDs may appear in the ticket context, there is no direct client-to-client exposure of order data.Recommendations
Update to version 0.8.0.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fossbilling