Executive brief
The Open ISES Project (now known as Tickets CAD) is an open-source computer-aided dispatch system used by emergency services and volunteer organizations to manage incidents and personnel. A security flaw in the software allows unauthorized individuals to download sensitive files directly from the server. This could lead to the exposure of critical configuration data, system files, and potentially private information about emergency responders or operations.
Technical details
A path traversal vulnerability exists in the 'ajax/download.php' component of The Open ISES Project version 3.30A. The application fails to properly sanitize the 'filename' parameter, allowing unauthenticated remote attackers to use directory traversal sequences (e.g., '../') to escape the intended directory. By exploiting this, an attacker can read arbitrary files on the host filesystem, including 'config.php' or sensitive OS files like 'win.ini', depending on the server environment. The vulnerability is reachable via a simple GET request and requires no user interaction. While the project has since evolved into 'Tickets CAD' and released newer versions (e.g., v3.44.1), users of legacy versions should upgrade immediately.
Affected products
- The Open ISES Project Tickets CAD (Open ISES Project) 3.30A and earlier
Timeline
- 2018-10-18: disclosed: Initial discovery and proof of concept by Ihsan Sencan
- 2026-05-30: advisory: CVE record published and enriched by VulnCheck