Junglewise Threat Intelligence

CVE-2026-48218: Open ISES Tickets reflected XSS in landb.php

CVE-2026-48218 · Severity: medium · CVSS 5.4 · Published 2026-05-21

Technologies: Open ISES Tickets. Vendors: Open ISES.

Executive brief

Open ISES Tickets, an open-source ticketing and incident management system, contains a security flaw in its web interface. An authenticated attacker can trick another user into executing malicious code in their browser, potentially leading to unauthorized actions or the theft of sensitive session information. This issue affects versions prior to 3.44.2 and can be resolved by updating to the latest version.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Open ISES Tickets versions prior to 3.44.2. The vulnerability is located in the 'icons/buttons/landb.php' component, which fails to properly sanitize the 'frm_name' and 'frm_id' POST parameters before rendering them into HTML and inline JavaScript. An authenticated attacker can exploit this by crafting a malicious request that, when processed by a victim's browser, executes arbitrary JavaScript in the context of the victim's session. This can lead to session hijacking or unauthorized data modification. The issue was addressed in version 3.44.2 by implementing proper input validation and output encoding (using htmlspecialchars and intval).

Affected products

  • Open ISES Tickets before 3.44.2

Timeline

  • 2026-04-01: patched: Fix committed to repository
  • 2026-04-02: advisory: Release v3.44.2 published
  • 2026-05-21: disclosed: CVE published to NVD

References

Related threats