Executive brief
The Open ISES Project (Tickets CAD), an open-source computer-aided dispatch system used by emergency services and volunteer organizations, contains a security flaw. An unauthenticated attacker can exploit this vulnerability to access the underlying database without a password. This could lead to the exposure of sensitive operational data, responder information, and system credentials, potentially disrupting emergency coordination efforts.
Technical details
An SQL injection vulnerability exists in The Open ISES Project (Tickets CAD) version 3.30A and earlier due to improper neutralization of special elements in SQL commands (CWE-89). The flaw is located in the 'nearby.php' component, specifically within the 'tick_lat' and 'tick_lng' parameters. An unauthenticated remote attacker can send crafted GET requests to these parameters to execute arbitrary SQL queries. This allows for the extraction of sensitive database information, including database names, version details, and user credentials. Proof-of-concept exploits also indicate similar vulnerabilities in 'main.php', 'form_post.php', and various graphing components.
Affected products
- Open ISES Project The Open ISES Project (Tickets CAD) 3.30A and earlier
Timeline
- 2018-10-18: disclosed: Initial exploit and vulnerability details shared on Exploit-DB
- 2026-05-29: advisory: CVE-2018-25399 published/updated in NVD