Executive brief
Open ISES Tickets is an open-source ticketing system used for managing support requests and incident tracking. A security flaw in the system allows an attacker to run malicious scripts in the web browser of a logged-in user. This could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in Open ISES Tickets versions prior to 3.44.2. The flaw is located in the 'add_nm.php' component, where the 'ticket_id' POST parameter is processed without sufficient sanitization. An authenticated attacker can exploit this by crafting a malicious request that embeds a JavaScript payload into an HTML form input's value attribute or an inline JavaScript string literal. When a victim views the resulting page, the payload executes in their browser context. The vendor has addressed this in version 3.44.2 by implementing input validation using the 'intval()' function for numeric parameters.
Affected products
- Open ISES Tickets before 3.44.2
Timeline
- 2026-04-01: patched: Fix committed to GitHub repository.
- 2026-04-02: advisory: Version 3.44.2 released.
- 2026-05-21: disclosed: CVE-2026-48214 published.