Junglewise Threat Intelligence

CVE-2026-48223: Open ISES Tickets reflected XSS in ics213rr.php

CVE-2026-48223 · Severity: medium · CVSS 5.4 · Published 2026-05-21

Technologies: Open ISES Tickets. Vendors: Open ISES.

Executive brief

Open ISES Tickets, a ticketing system used for incident management, contains a security flaw that allows attackers to run malicious scripts in a user's browser. By tricking an authenticated user into submitting a specially crafted request, an attacker could steal login session information or perform unauthorized actions on the user's behalf. This issue affects versions prior to 3.44.2, and organizations should upgrade to the latest version to protect their data and operations.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Open ISES Tickets before version 3.44.2. The flaw is located in the ics213rr.php component, where the 'frm_add_str' POST parameter is not properly sanitized before being rendered into an HTML form's hidden input value attribute. An authenticated attacker can exploit this by crafting a malicious request containing a JavaScript payload. When a victim processes this request, the payload executes within the context of their browser session, potentially allowing for session hijacking or unauthorized data access. This was patched in version 3.44.2 by implementing proper output encoding using htmlspecialchars().

Affected products

  • Open ISES Tickets before 3.44.2

Timeline

  • 2026-04-01: patched: Fix committed to GitHub repository.
  • 2026-04-02: advisory: Release v3.44.2 published.
  • 2026-05-21: disclosed: CVE-2026-48223 published.

References

Related threats