IDOR Vulnerability in FOSSBilling Billing System
CVE-2025-64105

5.1MEDIUM

Key Information:

Vendor
CVE Published:
23 June 2026

What is CVE-2025-64105?

FOSSBilling, a billing and client management system, contains a vulnerability that allows authenticated clients to create support tickets referencing other clients' orders through the manipulation of rel_id when rel_type=order. This flaw exists in versions 0.6.21 to 0.7.2, where the ticketCreateForClient() method does not perform ownership verification for non-upgrade tasks. Although client-to-client data exposure is mitigated, order IDs can be misrepresented in ticket contexts, potentially misleading staff during cancellation or upgrade processes. The vulnerability has been addressed in version 0.8.0.

Affected Version(s)

FOSSBilling >= 0.6.21, < 0.8.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.