Junglewise Threat Intelligence

CVE-2026-48222: Open ISES Tickets reflected XSS in ics213.php

CVE-2026-48222 · Severity: medium · CVSS 5.4 · Published 2026-05-21

Technologies: Open ISES Tickets. Vendors: Open ISES.

Executive brief

Open ISES Tickets, a ticketing system used for incident management, contains a security flaw in its handling of web forms. An attacker can trick a logged-in user into executing malicious scripts within their own browser session. This could lead to unauthorized actions being performed on behalf of the user or the theft of sensitive session information.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Open ISES Tickets versions prior to 3.44.2. The flaw is located in the ics213.php component, where the 'frm_add_str' POST parameter is not properly sanitized before being rendered into an HTML hidden input's value attribute. An authenticated attacker can exploit this by crafting a malicious request containing a JavaScript payload. When a victim processes this request, the payload executes in the context of their browser session, potentially allowing for session hijacking or unauthorized data modification. The issue was addressed in version 3.44.2 by implementing proper output encoding using htmlspecialchars().

Affected products

  • Open ISES Tickets < 3.44.2

Timeline

  • 2026-04-01: patched: Fix committed to repository
  • 2026-04-02: advisory: Release v3.44.2 published
  • 2026-05-21: disclosed: CVE published and NVD entry created

References

Related threats