Junglewise Threat Intelligence

CVE-2026-35013: Open ISES Tickets reflected XSS in street_view.php

CVE-2026-35013 · Severity: medium · CVSS 4.6 · Published 2026-05-20

Technologies: Open ISES Tickets. Vendors: Open ISES.

Executive brief

Open ISES Tickets is an open-source incident and service management system. A security flaw in its street view component allows attackers to send a specially crafted link to a logged-in user that, when clicked, executes malicious code in their browser. This could allow an attacker to perform actions on behalf of the user or steal sensitive session information.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Open ISES Tickets versions prior to 3.44.2. The vulnerability is located in street_view.php, where the 'thelat' and 'thelng' GET parameters are passed directly into JavaScript variable assignments without proper sanitization or encoding. An authenticated attacker can exploit this by crafting a malicious URL containing a JavaScript payload. When a victim visits this URL, the payload executes within the context of their browser session. The vendor has addressed this in version 3.44.2 by implementing floatval() casting for coordinate parameters and htmlspecialchars() for other affected inputs.

Affected products

  • Open ISES Tickets before 3.44.2

Timeline

  • 2026-04-01: patched: Fix committed to repository
  • 2026-04-02: advisory: Release v3.44.2 published
  • 2026-05-20: disclosed: CVE-2026-35013 published

References

Related threats