Junglewise Threat Intelligence

CVE-2026-48215: Open ISES Tickets reflected XSS in circle.php

CVE-2026-48215 · Severity: medium · CVSS 5.4 · Published 2026-05-21

Technologies: Open ISES Tickets. Vendors: Open ISES.

Executive brief

Open ISES Tickets, an open-source ticketing and incident management system, is vulnerable to a security flaw where malicious code can be injected into the application. An attacker with a valid account can send a specially crafted request that executes unauthorized scripts in the browser of another user. This could lead to the theft of session information, unauthorized actions on behalf of the user, or the defacement of the application interface.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Open ISES Tickets versions prior to 3.44.2. The flaw is located in the 'circle.php' component, which fails to sanitize the 'frm_id' POST parameter before reflecting it into an HTML form input's value attribute. An authenticated attacker can exploit this by crafting a malicious request containing a JavaScript payload. When a victim views the rendered response, the payload executes within the context of their browser session. The vendor has addressed this in version 3.44.2 by implementing proper input validation and output encoding (specifically using htmlspecialchars and intval across various affected files).

Affected products

  • Open ISES Tickets before 3.44.2

Timeline

  • 2026-04-01: patched: Fixes committed to repository
  • 2026-04-02: advisory: Release v3.44.2 published
  • 2026-05-21: disclosed: CVE published to NVD

References

Related threats