Vulnerability Description
Two unauthenticated diagnostic endpoints allow arbitrary backend-initiated network connections to an attacker‑supplied destination. Both endpoints are exposed with permission => 'any', enabling unauthenticated SSRF for internal network scanning and service interaction. This issue affects OpenSupports: 4.11.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Opensupports | Opensupports | 4.11.0 |
Related Weaknesses (CWE)
References
- https://fluidattacks.com/advisories/freerExploitThird Party Advisory
- https://github.com/opensupports/opensupportsProduct
- https://fluidattacks.com/advisories/freerExploitThird Party Advisory
FAQ
What is CVE-2025-10695?
CVE-2025-10695 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Two unauthenticated diagnostic endpoints allow arbitrary backend-initiated network connections to an attacker‑supplied destination. Both endpoints are exposed with permission => 'any', enabling unauth...
How severe is CVE-2025-10695?
CVE-2025-10695 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-10695?
Check the references section above for vendor advisories and patch information. Affected products include: Opensupports Opensupports.