Executive brief
Open ISES Tickets, an open-source incident management and ticketing system, is vulnerable to a security flaw where malicious code can be injected into the application. An authenticated attacker can trick a user into clicking a link or submitting a form that executes unauthorized JavaScript in their browser. This could lead to the theft of session cookies, unauthorized actions performed on behalf of the user, or the defacement of the application interface.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in Open ISES Tickets versions prior to 3.44.2. The flaw is located in the ics205a.php component, which fails to properly sanitize the 'frm_add_str' POST parameter before reflecting it into an HTML hidden input value attribute. An authenticated attacker can exploit this by crafting a malicious request containing a JavaScript payload. When a victim processes this request, the payload executes within the context of their browser session. This can be used to bypass same-origin policy protections and access sensitive session data. The issue was addressed in version 3.44.2 by implementing proper output encoding using htmlspecialchars().
Affected products
- Open ISES Tickets before 3.44.2
Timeline
- 2026-04-01: patched: Fix committed to repository
- 2026-04-02: advisory: Release v3.44.2 published
- 2026-05-21: disclosed: CVE-2026-48221 published