SQL Injection Vulnerability in OpenSupports Affected by Improper Parameter Handling
CVE-2025-10692
What is CVE-2025-10692?
The OpenSupports application has a vulnerability in its API that allows authenticated staff users to exploit improper parameter handling. Specifically, the POST /api/staff/get-new-tickets endpoint directly incorporates user-controlled input (departmentId) into the SQL query without the safety of parameter binding. This flaw permits an attacker with sufficient access rights to manipulate the SQL query and view tickets that should be restricted based on their department, leading to potential exposure of sensitive information. The issue has been identified in OpenSupports version 4.11.0, highlighting the need for developers to implement secure coding practices to safeguard against SQL injection attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
OpenSupports Windows 4.11.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
