Executive brief
Open ISES Tickets, a ticketing system used for incident management, is vulnerable to a security flaw that allows attackers to run malicious scripts in a user's browser. By tricking a logged-in user into clicking a specially crafted link, an attacker could steal session information or perform unauthorized actions on the user's behalf. This issue affects versions prior to 3.44.2 and could lead to unauthorized access to sensitive ticket data.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in Open ISES Tickets versions prior to 3.44.2. The flaw is located in the 'patient_JF.php' component, where the 'ticket_id' GET parameter is processed without sufficient sanitization before being assigned to a JavaScript variable. An authenticated attacker can exploit this by crafting a malicious URL containing a JavaScript payload. When a victim visits this URL, the payload executes within the context of their browser session. The vulnerability was addressed in version 3.44.2 by implementing proper input validation using the 'intval()' function.
Affected products
- Open ISES Tickets before 3.44.2
Timeline
- 2026-04-01: patched: Fix committed to GitHub repository
- 2026-04-02: advisory: Release v3.44.2 published
- 2026-05-20: disclosed: CVE published and NVD entry created