IDOR Vulnerability in FOSSBilling Billing System
CVE-2025-64105
5.1MEDIUM
What is CVE-2025-64105?
FOSSBilling, a billing and client management system, contains a vulnerability that allows authenticated clients to create support tickets referencing other clients' orders through the manipulation of rel_id when rel_type=order. This flaw exists in versions 0.6.21 to 0.7.2, where the ticketCreateForClient() method does not perform ownership verification for non-upgrade tasks. Although client-to-client data exposure is mitigated, order IDs can be misrepresented in ticket contexts, potentially misleading staff during cancellation or upgrade processes. The vulnerability has been addressed in version 0.8.0.
Affected Version(s)
FOSSBilling >= 0.6.21, < 0.8.0
