Junglewise Threat Intelligence

CVE-2026-35011: Open ISES Tickets reflected XSS in opena.php

CVE-2026-35011 · Severity: medium · CVSS 4.6 · Published 2026-05-20

Technologies: Open ISES Tickets. Vendors: Open ISES.

Executive brief

Open ISES Tickets is an open-source incident and ticket management system. A security flaw in the software allows an attacker to execute malicious scripts in the web browser of a logged-in user. This could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Open ISES Tickets before version 3.44.2. The vulnerability is located in the 'opena.php' file, where the 'frm_call' GET parameter is processed and rendered into the page output without sufficient sanitization or encoding. An authenticated attacker can exploit this by crafting a malicious URL containing a JavaScript payload. When a victim visits this URL, the payload executes within the context of their browser session. The vendor has addressed this in version 3.44.2 by implementing htmlspecialchars() for string values in HTML attributes and intval() for numeric identifiers.

Affected products

  • Open ISES Tickets before 3.44.2

Timeline

  • 2026-04-01: patched: Fix committed to GitHub repository
  • 2026-04-02: advisory: Release v3.44.2 published
  • 2026-05-20: disclosed: CVE-2026-35011 published

References

Related threats