Junglewise Threat Intelligence

CVE-2026-48219: Open ISES Tickets reflected XSS in ics202.php

CVE-2026-48219 · Severity: medium · CVSS 5.4 · Published 2026-05-21

Technologies: Open ISES Tickets. Vendors: Open ISES.

Executive brief

Open ISES Tickets, an incident management and ticketing system, contains a security flaw that could allow an attacker to execute malicious scripts in another user's browser. By tricking a logged-in user into submitting a specially crafted web request, an attacker could potentially steal session information or perform unauthorized actions on behalf of that user. This issue affects versions prior to 3.44.2, and organizations are advised to upgrade to the latest version to protect their operations.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Open ISES Tickets versions prior to 3.44.2. The flaw is located in the ics202.php component, where the 'frm_add_str' POST parameter is processed without sufficient sanitization before being rendered into an HTML hidden input's value attribute. An authenticated attacker can exploit this by crafting a malicious request containing a JavaScript payload. When a victim user is coerced into submitting this request (typically via social engineering), the payload executes within the context of the victim's browser session. This can lead to session hijacking or unauthorized data modification. The issue was addressed in version 3.44.2 by implementing proper output encoding using htmlspecialchars().

Affected products

  • Open ISES Tickets before 3.44.2

Timeline

  • 2026-04-01: patched: Fix committed to repository
  • 2026-04-02: advisory: Release v3.44.2 published
  • 2026-05-21: disclosed: CVE published to NVD

References

Related threats